Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
BID:29579
Info
Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 29579 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2684 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | shinnai <[email protected]> |
| Vulnerable: |
Black Ice Software TIFF SDK/ActiveX 0 Black Ice Software Document Imaging SDK/ActiveX 0 Black Ice Software BiDib.dll 10.9.3 .0 Black Ice Software Barcode SDK/ActiveX 0 |
| Not Vulnerable: | |
Discussion
Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
Multiple Black Ice Software applications are prone to a stack-based buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects applications that include BiDib.dll 10.9.3.0; other versions may also be affected.
Multiple Black Ice Software applications are prone to a stack-based buffer-overflow vulnerability because they fail to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects applications that include BiDib.dll 10.9.3.0; other versions may also be affected.
Exploit / POC
Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
Solution / Fix
Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Black Ice Multiple Applications 'BiDib.dll ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Black Ice Software)