Overview
The Aurigma ImageUploader ActiveX control contains multiple stack buffer overflow vulnerabilities, which may allow a remote attacker to execute arbitrary code on a vulnerable system.
Description
Aurigma ImageUploader is an ActiveX control that provides the ability to upload pictures using the Internet Explorer web browser. The Aurigma ImageUploader ActiveX control is used by multiple web sites, such as Facebook and MySpace. This ActiveX control contains multiple stack buffer overflows in several properties, including Action, ExtractExif, and ExtractIptc. Limited testing has shown that versions up to and including version 5.0.30 may be vulnerable. Exploit code is publicly available. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user on a vulnerable system. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://blogs.aurigma.com/post/2008/03/Official-security-bulletin.aspx
- http://blogs.aurigma.com/post/2008/03/Image-Uploader-reborns---better-security-and-new-CLSIDs.aspx
- http://www.microsoft.com/technet/security/advisory/953839.mspx
- http://seclists.org/fulldisclosure/2008/Jan/0593.html
- http://seclists.org/fulldisclosure/2008/Feb/0023.html
- http://secunia.com/advisories/28733/
- http://www.securityfocus.com/bid/27533
- http://blogs.aurigma.com/post/2008/01/Another-security-problem---oh%2c-not-again.aspx
- http://secunia.com/advisories/28707/
- http://secunia.com/advisories/28713/
Acknowledgements
This vulnerability was publicly disclosed by Elazar Broad.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2008-0660, CVE-2008-0659 |
Severity Metric: | 16.07 |
Date Public: | 2007-11-22 |
Date First Published: | 2008-02-04 |
Date Last Updated: | 2008-08-13 20:31 UTC |
Document Revision: | 21 |