|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Thu Feb 11 2010 - 14:17:10 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----------------------------------------------------------------------
Secunia integrated with Microsoft WSUS
http://secunia.com/blog/71/
----------------------------------------------------------------------
TITLE:
Hyleos ChemView ActiveX Control Buffer Overflow Vulnerabilities
SECUNIA ADVISORY ID:
SA38523
VERIFY ADVISORY:
http://secunia.com/advisories/38523/
DESCRIPTION:
Paul Craig has discovered some vulnerabilities in the Hyleos ChemView
ActiveX control, which can be exploited by malicious people to
compromise a user's system.
The vulnerabilities are caused due to two boundary errors in the
HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx). These
can be exploited to cause stack-based buffer overflows by passing
strings containing an overly large number of white-space characters
to the "SaveasMolFile()" and "ReadMolFile()" methods.
Successful exploitation allows execution of arbitrary code.
The vulnerabilities are confirmed in HyleosChemView.ocx version
1.9.5.1. Other versions may also be affected.
SOLUTION:
Set the kill-bit for the affected ActiveX control.
PROVIDED AND/OR DISCOVERED BY:
Paul Craig, Security-Assessment
ORIGINAL ADVISORY:
http://www.security-assessment.com/files/advisories/2010-02-11_ChemviewX_Activex.pdf
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]