OSVDB ID: 36715

Title: Zenturi ProgramChecker sasatl.dll ActiveX Multiple Method Overflow

Info

Disclosure

May 29, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Multiple buffer overflows exists in Zenturi Program Checker. The sasatl.dll ActiveX control fails to validate data passed to the DebugMsgLog and DoFileProperties methods resulting in a stack overflow. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure
OSVDB: Web Related

Solution

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: set the kill-bit on the below ActiveX Controls. See Microsoft KB article 240797 for more details. {048313BB-3B82-47A8-8164-533F1D7C7C9D} {0FA0B4FF-1A6F-4D89-995C-29FFD33F4EE0} {59DBDDA6-9A80-42A4-B824-9BC50CC172F5} {66C7B32A-9642-41A4-BCF7-A166D1547770} {6754F588-E262-42D2-A6BC-3BB400ACFEED} {7D6B5B24-FC7E-11D1-9288-00104B885781} {A364AF35-0CDF-41E8-8F3B-E0E55E15EBA1}

Products

Zenturi, Inc.

ProgramChecker

Unspecified

References

Credit

  • Will Dormann -   -


Direct URL: http://osvdb.org/36218