Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
BID:71486
Info
Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 71486 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-9265 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2014 12:00AM |
| Updated: | Jan 22 2015 02:04PM |
| Credit: | Andrea Micalizzi (rgod) |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
Samsung SmartViewer is prone to a stack buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it into a fixed-size buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Samsung SmartViewer is prone to a stack buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it into a fixed-size buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
The following exploit code is available.
The following exploit code is available.
Solution / Fix
Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samsung SmartViewer 'CNC_Ctrl' ActiveX Stack Buffer Overflow Vulnerability
References:
References: