Thursday, September 27, 2007 3:53 PM cmosby

Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow - Advisories - Secunia

 

Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow
Advisory Available in Danish Advisory Available in German

Secunia Advisory:
SA26960

Release Date:
2007-09-25

Critical:

Highly critical

Impact:
System access

Where:
From remote

Solution Status:
Unpatched

Software:
Ask Toolbar 4.x

Description:
Joey Mengele has discovered a vulnerability in Ask Toolbar, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control (askBar.dll) when handling the "ShortFormat" property. This can be exploited to cause a stack-based buffer overflow by assigning an overly long (greater than 500 bytes) string to the affected property.

Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in version 4.0.2. Other versions may also be affected.

Solution:
Set the kill-bit for the affected ActiveX control.

Provided and/or discovered by:
Joey Mengele

Original Advisory:
http://www.milw0rm.com/exploits/4452

Source: Ask Toolbar ToolbarSettings ActiveX Control Buffer Overflow - Advisories - Secunia

Filed under: ,

Comments

No Comments