Thursday, September 27, 2007 3:53 PM
cmosby
Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow - Advisories - Secunia
Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow
Secunia Advisory:
SA26960
Release Date:
2007-09-25
Critical:

Highly critical
Impact:
System access
Where:
From remote
Solution Status:
Unpatched
Software:
Ask Toolbar 4.x
Description:
Joey Mengele has discovered a vulnerability in Ask Toolbar, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control (askBar.dll) when handling the "ShortFormat" property. This can be exploited to cause a stack-based buffer overflow by assigning an overly long (greater than 500 bytes) string to the affected property.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 4.0.2. Other versions may also be affected.
Solution:
Set the kill-bit for the affected ActiveX control.
Provided and/or discovered by:
Joey Mengele
Original Advisory:
http://www.milw0rm.com/exploits/4452
Source: Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow - Advisories - Secunia
Filed under: Security and Anti-Virus, Internet Applications