Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
BID:48585
Info
Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
| Bugtraq ID: | 48585 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2011 12:00AM |
| Updated: | Jul 06 2011 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
Diego Uscanga aTube Catcher 2.3.570 Chilkat Chilkat Crypt ActiveX 2.1 |
| Not Vulnerable: | |
Discussion
Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
Chilkat Crypt ActiveX control is prone to a vulnerability caused by an insecure method that let attackers overwrite files with arbitrary, attacker-controlled content.
Successfully exploiting this issue allows remote attackers to overwrite arbitrary files in the context of the application (typically Internet Explorer) using the ActiveX control.
Chilkat Crypt ActiveX control is prone to a vulnerability caused by an insecure method that let attackers overwrite files with arbitrary, attacker-controlled content.
Successfully exploiting this issue allows remote attackers to overwrite arbitrary files in the context of the application (typically Internet Explorer) using the ActiveX control.
Exploit / POC
Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
To exploit these issues, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following exploit code is available:
To exploit these issues, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following exploit code is available:
Solution / Fix
Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Chilkat Crypt ActiveX Control 'SaveDecrypted()' Insecure Method Vulnerability
References:
References:
- aTube Catcher ActiveX Control Insecure Method (High-Tech Bridge SA)
- aTube Catcher Homepage (Diego Uscanga)
- Chilkat Software Homepage (Chilkat Software)
- aTube Catcher ActiveX Control Insecure Method (High-Tech Bridge SA)