NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
BID:32105
Info
NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 32105 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4817 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Mar 19 2015 08:52AM |
| Credit: | Peter Vreugdenhil |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE Linux Enterprise Server RT Solution 10 0 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc64 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client NOS Microsystems getPlus Download Manager 1.2.2 50 NOS Microsystems getPlus Download Manager 0 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Gentoo Linux Avaya IR 3.0 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Adobe Reader 8.1.2 Adobe Reader 8.1.1 Adobe Reader 7.0.9 Adobe Reader 7.0.8 Adobe Reader 7.0.7 Adobe Reader 7.0.6 Adobe Reader 7.0.5 Adobe Reader 7.0.4 Adobe Reader 7.0.3 Adobe Reader 7.0.2 Adobe Reader 7.0.1 Adobe Reader 7.0 Adobe Reader 6.0.4 Adobe Reader 6.0.3 Adobe Reader 6.0.2 Adobe Reader 6.0.1 Adobe Reader 6.0 Adobe Reader 8.1.2 Security Updat Adobe Reader 8.1 Adobe Reader 8.0 Adobe Reader 7.1 Adobe Acrobat Standard 8.1.2 Adobe Acrobat Standard 8.1.1 Adobe Acrobat Standard 7.0.8 Adobe Acrobat Standard 7.0.7 Adobe Acrobat Standard 7.0.6 Adobe Acrobat Standard 7.0.5 Adobe Acrobat Standard 7.0.4 Adobe Acrobat Standard 7.0.3 Adobe Acrobat Standard 7.0.2 Adobe Acrobat Standard 7.0.1 Adobe Acrobat Standard 7.0 Adobe Acrobat Standard 8.1 Adobe Acrobat Standard 8.0 Adobe Acrobat Standard 7.1 Adobe Acrobat Professional 8.1.2 Adobe Acrobat Professional 8.1.1 Adobe Acrobat Professional 7.0.9 Adobe Acrobat Professional 7.0.8 Adobe Acrobat Professional 7.0.7 Adobe Acrobat Professional 7.0.6 Adobe Acrobat Professional 7.0.5 Adobe Acrobat Professional 7.0.4 Adobe Acrobat Professional 7.0.3 Adobe Acrobat Professional 7.0.2 Adobe Acrobat Professional 7.0.1 Adobe Acrobat Professional 7.0 Adobe Acrobat Professional 8.1.2 Security Updat Adobe Acrobat Professional 8.1 Adobe Acrobat Professional 8.0 Adobe Acrobat Professional 7.1 Adobe Acrobat Professional 6.0 Adobe Acrobat 3D 8.1.2 Adobe Acrobat 3D 0 |
| Not Vulnerable: |
Adobe Reader 8.1.3 Adobe Reader 9 Adobe Acrobat Standard 8.1.3 Adobe Acrobat Standard 9 Adobe Acrobat 3D 8.1.3 |
Discussion
NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
NOS Microsystems getPlus Download Manager ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
The following applications use the getPlus Download Manager:
Adobe Acrobat Professional
Adobe Acrobat Reader
getPlus Download Manager 1.2.2.50 is vulnerable; other versions may also be affected.
NOS Microsystems getPlus Download Manager ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
The following applications use the getPlus Download Manager:
Adobe Acrobat Professional
Adobe Acrobat Reader
getPlus Download Manager 1.2.2.50 is vulnerable; other versions may also be affected.
Exploit / POC
NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
Solution:
Adobe has fixed this issue in the latest versions of Acrobat and Reader. Please see the references for more information.
Solution:
Adobe has fixed this issue in the latest versions of Acrobat and Reader. Please see the references for more information.
References
NOS Microsystems getPlus Download Manager ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- getPlus Download Manager Homepage (NOS Microsystems)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Multiple Vendor NOS Microsystems getPlus Downloader Stack Buffer Overflow Vulner (iDefense Labs)
- Security Update available for Adobe Reader 8 and Acrobat 8 (Adobe)
- iDefense Security Advisory 11.04.08: Multiple Vendor NOS Microsystems getPlus Do (iDefense Labs
) - Nortel Response to Adobe Vulnerability Identifier APSB08-19 (Nortel Networks)
- ASA-2009-018 Multiple Security Vulnerabilities in the Adobe Reader May Lead to E (Avaya)
- Nortel Response to Sun Alert 249366 - Solaris 10 - Multiple Security Vulnerabili (Nortel Networks)
- Solution 249366: Multiple Security Vulnerabilities in the Adobe Reader May Lead (Sun)