Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
BID:29446
Info
Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 29446 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2008 12:00AM |
| Updated: | Nov 13 2008 08:54PM |
| Credit: | The original discoverer is unknown. Symantec has observed exploits in the wild. |
| Vulnerable: |
Ourgame GLIEDown2.dll 0 GlobalLink GlobalLink 2.8.1.2 beta |
| Not Vulnerable: | |
Discussion
Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
Ourgame 'GLIEDown2.dll' ActiveX control is prone to a remote code-execution vulnerability because it fails to sufficiently verify user-supplied input.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
Note that GlobalLink 2.8.1.2 beta is also affected by this issue.
Ourgame 'GLIEDown2.dll' ActiveX control is prone to a remote code-execution vulnerability because it fails to sufficiently verify user-supplied input.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
Note that GlobalLink 2.8.1.2 beta is also affected by this issue.
Exploit / POC
Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
Symantec has observed exploits in the wild.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
Symantec has observed exploits in the wild.
Solution / Fix
Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code Execution Vulnerability
References:
References:
- GLIEDown2.dll Active (NSFOCUS)
- GlobalLink Homepage (GlobalLink)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Ourgame Homepage (Ourgame)