|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Full-Disclosure] BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure
From: Ovidiu Constantin (oconstantin
bitdefender.com)
Date: Tue Apr 20 2004 - 04:39:38 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
> Application: BitDefender Scan Online(ActiveX)
> Vendors: http://www.bitdefender.com/scan/Msie/index.php
> Platforms: Windows
> Bug: Remote File Download & Execute & Private Information
> Disclosure
> Risk: High - Running Arbitary Code
> Exploitation: Remote with browser
> Date: 19 Apr 2004
> Author: Rafel Ivgi, The-Insider
> e-mail: the_insider
mail.com
> web: http://theinsider.deep-ice.com
The problem was solved yesterday, the ActiveX control was updated. In order to
apply the update, a user has to access the scan online webpage (on
bitdefender.com or partner sites) and allow the update.
Btw... it would have been really nice not to expose users to this
vulnerability and let us know prior to making it public.
- --
Ovidiu Constantin
BitDefender Internal Testing Engineer
- -------------------------------------
SOFTWIN
Data Security Division
- -------------------------------------
e-mail: oconstantin
bitdefender.com
phone: +(4021) 233 18 52; 233 07 80
fax: (+4021) 233.07.63
Bucharest, ROMANIA
http://www.bitdefender.com
http://www.softwin.ro
- -------------------------------------
secure your every bit
- -------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFAhO/aa3h8kFS2shsRAsgqAKCFtT2ajCfqKdOmkW0fxdCm06IVmwCbBdW1
aMYxACETH6r0865qs/UzppM=
=510O
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]