Search:     Advanced search
server monitoring

SizerOne ActiveX Control AddTab Method Remote Buffer Overflow

Article ID: 35327
Last updated: 27 Jan, 2009
Views: 604
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

SizerOne ActiveX Control AddTab Method Remote Buffer Overflow

This script is Copyright (C) 2009 Tenable Network Security, Inc.

FamilyWindows
Plugin ID35327
Bugtraq ID33148
CVE IDCVE-2008-4827

Description:
Synopsis :

The remote Windows host has an ActiveX control that is affected by a
buffer overflow vulnerability.

Description :

The SizerOne ActiveX control is installed on the remote system. It is
included with ComponentOne Studio Enterprise as well as other
applications such as TSC2 Help Desk and SAP GUI.

The installed version of the control is affected by a heap-based
buffer overflow vulnerability that can be triggered by adding tabs
with very long captions via the controls AddTab() method. If a
remote attacker can trick a user on the affected host into viewing a
specially crafted HTML document, he may be able to leverage this issue
to execute arbitrary code on the affected host subject to the users
privileges.

See also :

http://secunia.com/secunia_research/2008-52
http://secunia.com/secunia_research/2008-53
http://secunia.com/secunia_research/2008-54

Solution :

Update to version 8.0.20081.142 of c1sizer.ocx or 7.10 PL of
sizerone.ocx.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
RealVNC VNC Viewer < 4.1.3/4.4.3 Arbitrary Command Execution     Altiris Deployment Solution < 6.9.176 Multiple Vulnerabilities...