UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
BID:42551
Info
UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
| Bugtraq ID: | 42551 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2970 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2009 12:00AM |
| Updated: | Oct 16 2009 12:00AM |
| Credit: | Yu Yang of NSFOCUS Security Team. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
UiPlayer is prone to a buffer-overflow vulnerability because the application utilize an ActiveX control that fails to adequately validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
UiTV UiPlayer 1.0.0.6 and prior versions are vulnerable; others may also be affected.
UiPlayer is prone to a buffer-overflow vulnerability because the application utilize an ActiveX control that fails to adequately validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
UiTV UiPlayer 1.0.0.6 and prior versions are vulnerable; others may also be affected.
Exploit / POC
UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
Solution:
Reportedly the vendor has fixed the issue. Please contact the vendor for more information.
Solution:
Reportedly the vendor has fixed the issue. Please contact the vendor for more information.
References
UiPlayer 'UiCheck.dll' ActiveX Buffer Overflow Vulnerability
References:
References:
- Home page (UiTV)
- NSFOCUS Security Advisory (SA2009-01) (NSFocus)