Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
BID:42248
Info
Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 42248 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-3737 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2010 12:00AM |
| Updated: | Aug 05 2010 12:00AM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: |
Oracle Siebel Option Pack for IE ActiveX Control 0 |
| Not Vulnerable: | |
Discussion
Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
Oracle Siebel Option Pack for IE ActiveX control is prone to a remote code-execution vulnerability caused by a memory-initialization error.
An attacker can exploit this issue to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed attacks will likely cause denial-of-service conditions.
Oracle Siebel Option Pack for IE ActiveX control is prone to a remote code-execution vulnerability caused by a memory-initialization error.
An attacker can exploit this issue to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Siebel Option Pack for IE ActiveX Control Remote Code Execution Vulnerability
References:
References: