NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
BID:29396
Info
NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 29396 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0959 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2008 12:00AM |
| Updated: | May 27 2008 12:00AM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: |
WMA to MP3 Converter 4U WMA MP3 Converter 6.2.6 Ussun Power Audio CD Grabber 1 Ussun Power Audio CD Burner 1 Orion Studios CinematicMP3 1 NCTsoft NCTAudioInformation2 ActiveX Control 0 My Phone Files Media Studio My Phone Files Media Studio 3.11 Media Solutions Powerful Audio Tool 1.03 Media Solutions Audio Editor Plus 3.1 Magic Soft Total Audio Recorder and Editor 4.8 Magic Soft Total Audio Capture 3.0 Crystal Software Crystal MP3 Recorder 1.00 Audiotool.net Ease Jukebox 1 Audioredact Mediasoft Easy Audio Redactor 1.1 AliveMedia Alive MP3 WAV Converter 3 |
| Not Vulnerable: | |
Discussion
NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
NCTSoft NCTAudioInformation2 ActiveX control is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
NOTE: Multiple third-party applications contain this ActiveX control and are also vulnerable. See the vulnerable systems section for details.
NCTSoft NCTAudioInformation2 ActiveX control is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
NOTE: Multiple third-party applications contain this ActiveX control and are also vulnerable. See the vulnerable systems section for details.
Exploit / POC
NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
An attacker would exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker would exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NCTSoft NCTAudioInformation2 ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- Alive MP3 WAV Converter Homepage (AliveMedia)
- Audiotool.net Homepage (Audiotool.net)
- CinematicMP3 Homepage (Orion Studios)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Power Audio CD Burner Homepage (Ussun)
- Power Audio CD Grabber Homepage (Ussun)
- Vendor Homepage (NCTSoft)
- Vulnerability Note VU#669265 (US-CERT)