WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
BID:56678
Info
WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 56678 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2012 12:00AM |
| Updated: | Nov 26 2012 12:00AM |
| Credit: | Francis Provencher via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
WibuKey is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input through an overly long string passed as the parameter to the method.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
WibuKey 6.00f Build 140 is vulnerable; other versions may also be affected.
WibuKey is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input through an overly long string passed as the parameter to the method.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
WibuKey 6.00f Build 140 is vulnerable; other versions may also be affected.
Exploit / POC
WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WibuKey Runtime ActiveX Control Stack Buffer Overflow Vulnerability
References:
References:
- WIBU-SYSTEMS AG HomePage (WIBU-SYSTEMS AG)
- WibuKey Product Page (WIBU-SYSTEMS AG)