Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
BID:33148
Info
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
| Bugtraq ID: | 33148 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4827 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | Jan 05 2010 09:02PM |
| Credit: | Carsten Eiram |
| Vulnerable: |
Servantix TSC2 Help Desk 4.1.8 SAP SAP GUI 7.10 SAP SAP GUI 6.40 Patch 29 ComponentOne Studio for ActiveX 2008 0 ComponentOne Studio Enterprise 2008 0 ComponentOne SizerOne 8.0.20081.140 |
| Not Vulnerable: |
Servantix TSC2 Help Desk 4.3.1 SAP SAP GUI 7.10 PL ComponentOne SizerOne 8.0.20081.142 |
Discussion
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
The SizerOne ActiveX control used in products by multiple vendors is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
The SizerOne ActiveX control used in products by multiple vendors is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
Exploit / POC
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
An attacker may exploit this issue by enticing a victim into visiting a malicious webpage.
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
An attacker may exploit this issue by enticing a victim into visiting a malicious webpage.
Solution / Fix
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
Solution:
Reports indicate that SAP GUI 7.10 PL and ComponentOne SizerOne 8.0.20081.142 are not affected by this issue. Symantec has not verified this information.
Solution:
Reports indicate that SAP GUI 7.10 PL and ComponentOne SizerOne 8.0.20081.142 are not affected by this issue. Symantec has not verified this information.
References
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
References:
References:
- ComponentOne SizerOne ActiveX Control Buffer Overflow (Secunia)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- SAP GUI Family (SAP)
- SAP GUI TabOne ActiveX Control Caption List Buffer Overflow (Secunia)
- SizerOne (ComponentOne)
- TSC2 Help Desk (Servantix)
- TSC2 Help Desk CTab ActiveX Control Buffer Overflow (Secunia)
- Re: Secunia Research: TSC2 Help Desk CTab ActiveX Control Buffer Overflow ([email protected])
- Secunia Research: TSC2 Help Desk CTab ActiveX Control Buffer Overflow (Secunia Research
) - Secunia Research: SAP GUI TabOne ActiveX Control Caption List Buffer Overflow (Secunia Research
)