DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
BID:65050
Info
DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
| Bugtraq ID: | 65050 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-7246 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2014 12:00AM |
| Updated: | Jan 07 2014 12:00AM |
| Credit: | Trustwave SpiderLabs |
| Vulnerable: |
Daum DaumGame ActiveX 1.1.0.5 Daum DaumGame ActiveX 1.1.0.4 |
| Not Vulnerable: |
Daum DaumGame ActiveX 1.1.0.6 |
Discussion
DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
DaumGame ActiveX plugin is prone to buffer overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied input.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
DaumGame ActiveX 1.1.0.5 and 1.1.0.4 are vulnerable.
DaumGame ActiveX plugin is prone to buffer overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied input.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
DaumGame ActiveX 1.1.0.5 and 1.1.0.4 are vulnerable.
Exploit / POC
DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
The researcher who discovered this issue has created a proof-of-concept code. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept code. Please see the references for more information.
Solution / Fix
DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
DaumGame ActiveX Plugin 'IconCreate' Method Buffer Overflow Vulnerability
References:
References:
- Daum Homepage (Daum)
- TWSL2014-002: Buffer Overflow Vulnerability in DaumGame ActiveX (Trustwave Advisories)