Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
BID:29577
Info
Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 29577 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2008 12:00AM |
| Updated: | Jun 05 2008 12:00AM |
| Credit: | shinnai <[email protected]> |
| Vulnerable: |
Black Ice Software TIFF SDK/ActiveX 0 Black Ice Software Document Imaging SDK/ActiveX 0 Black Ice Software BiDib.dll 10.9.3 .0 Black Ice Software Barcode SDK/ActiveX 0 |
| Not Vulnerable: | |
Discussion
Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
Multiple Black Ice Software applications are prone to a vulnerability that can cause malicious files
to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to overwrite sensitive files with malicious data that will compromise the affected computer. Other attacks are possible.
This issue affects applications that include BiDib.dll 10.9.3.0; other versions may also be affected.
Multiple Black Ice Software applications are prone to a vulnerability that can cause malicious files
to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to overwrite sensitive files with malicious data that will compromise the affected computer. Other attacks are possible.
This issue affects applications that include BiDib.dll 10.9.3.0; other versions may also be affected.
Exploit / POC
Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
Solution / Fix
Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Black Ice Software)