BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
BID:33663
Info
BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 33663 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0305 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2009 12:00AM |
| Updated: | Nov 03 2009 06:07PM |
| Credit: | Andre Protas and Greg Linares of eEye Research and Chris Weber of Casaba Security |
| Vulnerable: |
Rim BlackBerry Application Web Loader 1.0 |
| Not Vulnerable: |
Rim BlackBerry Application Web Loader 1.1 |
Discussion
BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
BlackBerry Application Web Loader ActiveX control is prone to a remote stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
BlackBerry Application Web Loader 1.0 is vulnerable.
BlackBerry Application Web Loader ActiveX control is prone to a remote stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
BlackBerry Application Web Loader 1.0 is vulnerable.
Exploit / POC
BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Research In Motion Homepage (Research In Motion)
- VU#131100: RIM BlackBerry Application Web Loader ActiveX stack buffer overflow (US-CERT)
- Microsoft Security Advisory 960715 (Microsoft)
- Vulnerability exists in BlackBerry Application Web Loader ActiveX control (Research In Motion)