Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
BID:48285
Info
Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
| Bugtraq ID: | 48285 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2011 12:00AM |
| Updated: | Jun 15 2011 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
Gogago YouTube Video Converter 1.1.6 |
| Not Vulnerable: | |
Discussion
Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
Gogago YouTube Video Converter ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
Gogago YouTube Video Converter 1.1.6 is vulnerable; other versions may also be affected.
Gogago YouTube Video Converter ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
Gogago YouTube Video Converter 1.1.6 is vulnerable; other versions may also be affected.
Exploit / POC
Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Gogago YouTube Video Converter ActiveX control 'Download()' Method Buffer Overflow Vulnerability
References:
References:
- YouTube Video Converter Homepage (Gogago)
- HTB23012: Gogago YouTube Video Converter ActiveX Control 'Download()' Buffer Ove ([[email protected]: HTB23012: Gogago YouTube Video Converter ActiveX Control )