- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
BearShare NCTAudioFile2 ActiveX Control Buffer Overflow
------------------------------------------------------------------------
SUMMARY
<http://www.bearshare.com/> BearShare allows you to "Share, Discover and
Download music and videos". Secunia Research has discovered a
vulnerability in BearShare, which can be exploited by malicious people to
compromise a user's system.
DETAILS
Vulnerable Systems:
* BearShare version 6.0.2.26789
The vulnerability is caused due to a boundary error in the
NCTAudioFile2.AudioFile ActiveX control when handling the
"SetFormatLikeSample()" method. This can be exploited to cause a
stack-based buffer overflow by passing an overly long string (about 4124
bytes) as argument to the affected method.
Successful exploitation allows execution of arbitrary code when a user
e.g. visits a malicious website.
Solution:
Set the kill-bit for the affected ActiveX control.
Time Table:
30/04/2007 - Vendor notified.
09/05/2007 - Public disclosure.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0018>
CVE-2007-0018
ADDITIONAL INFORMATION
The information has been provided by <mailto:vuln@secunia.com> Secunia
Research.
The original article can be found at:
<http://secunia.com/secunia_research/2007-50/>
http://secunia.com/secunia_research/2007-50/
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
No comments:
Post a Comment