BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
BID:29558
Info
BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 29558 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0956 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2008 12:00AM |
| Updated: | Jun 10 2008 11:42PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Logitech Logitech Desktop Manager 2.55 BackWeb BackWeb 8.1.1.86 |
| Not Vulnerable: |
Logitech Logitech Desktop Manager 2.56 BackWeb BackWeb 8.1.1.87 |
Discussion
BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
BackWeb is prone to a remote buffer-overflow vulnerability because of a flaw in one of its ActiveX control components. The issue occurs because the component fails to perform adequate boundary checks on user-supplied input before copying it to a buffer.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
This issue affects versions prior to BackWeb 8.1.1.87.
BackWeb is prone to a remote buffer-overflow vulnerability because of a flaw in one of its ActiveX control components. The issue occurs because the component fails to perform adequate boundary checks on user-supplied input before copying it to a buffer.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
This issue affects versions prior to BackWeb 8.1.1.87.
Exploit / POC
BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
Solution:
The vendor released BackWeb 8.1.1.87 to address this issue. Please see the references for more information.
Solution:
The vendor released BackWeb 8.1.1.87 to address this issue. Please see the references for more information.
References
BackWeb 'LiteInstActivator.dll' ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Desktop Manager Download Page (Logitech)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (BackWeb)
- Important Security Update (BackWeb)
- Microsoft Security Bulletin MS08-032 (Microsoft)
- VU#216153 BackWeb Lite Install Runner ActiveX stack buffer overflows (US-CERT)