Tom Sawyer Software GET Extension Factory Object Initialization Memory Corruption Vulnerability
BID:48099
Info
Tom Sawyer Software GET Extension Factory Object Initialization Memory Corruption Vulnerability
| Bugtraq ID: | 48099 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2217 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2011 12:00AM |
| Updated: | Mar 19 2015 09:15AM |
| Credit: | Elazar Broad and iDefense |
| Vulnerable: |
VMWare Infrastructure Client 2.4 VMWare Infrastructure Client 2.0 Tom Sawyer Software GET Extension Factory 5.5.2.237 Embarcadero Technologies ER/Studio XE2 0 |
| Not Vulnerable: |
VMWare VirtualCenter 2.5 Update 6a VMWare VirtualCenter 2.5 Update 6 VMWare Infrastructure Client 2.5 Build 204931 VMWare Infrastructure Client 2.0.2 Build 230598 |
Discussion
Tom Sawyer Software GET Extension Factory Object Initialization Memory Corruption Vulnerability
Tom Sawyer Software GET Extension Factory is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
NOTE (June 3, 2011): This BID was previously titled 'VMware Infrastructure (VI) Client ActiveX Object Memory Corruption Vulnerability' but has been rewritten to better reflect the underlying issue.
Tom Sawyer Software GET Extension Factory is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
NOTE (June 3, 2011): This BID was previously titled 'VMware Infrastructure (VI) Client ActiveX Object Memory Corruption Vulnerability' but has been rewritten to better reflect the underlying issue.
Exploit / POC
Tom Sawyer Software GET Extension Factory Object Initialization Memory Corruption Vulnerability
An attacker can exploit this issue using a browser.
The following exploit is available:
An attacker can exploit this issue using a browser.
The following exploit is available:
Solution / Fix
Tom Sawyer Software GET Extension Factory Object Initialization Memory Corruption Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.