Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
BID:31783
Info
Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
| Bugtraq ID: | 31783 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4729 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Thomas Pollet |
| Vulnerable: |
Hummingbird HostExplorer 8.0 Hummingbird HostExplorer 6.2 |
| Not Vulnerable: |
Hummingbird HostExplorer 2008 |
Discussion
Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
Hummingbird HostExplorer ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Hummingbird HostExplorer ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
Solution / Fix
Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
Solution:
This issue is reported to be fixed in version 13.0 of the HostExplorer ActiveX control. Symantec has not been able to confirm this information.
Solution:
This issue is reported to be fixed in version 13.0 of the HostExplorer ActiveX control. Symantec has not been able to confirm this information.
References
Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer Overflow Vulnerability
References:
References:
- HostExplorer Homepage (Hummingbird)
- Microsoft Knowledge Base Article 240797 (Microsoft)