CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
BID:55379
Info
CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
| Bugtraq ID: | 55379 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2012 12:00AM |
| Updated: | Sep 03 2012 12:00AM |
| Credit: | Blake |
| Vulnerable: |
CyberLink SoftDMA 2.0.4213 CyberLink PowerDVD 12.0.1620.54 CyberLink KoanBox ActiveX Control 1.0.3787.4614 |
| Not Vulnerable: | |
Discussion
CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
CyberLink KoanBox ActiveX Control is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
CyberLink KoanBox ActiveX Control is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CyberLink KoanBox ActiveX Control 'koanbox.dll' ActiveX Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- PowerDVD Homepage (cyberlink)
- SoftDMA Homepage (CyberLink)