Name:
Lycos.File.Upload.ActiveX.Access
Released Date:
Jan 29 2008
Severity:
critical
CVE:
2008-0443
Bugtraq:
27411

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit a buffer overflow vulnerability in Lycos File Upload ActiveX control.

The vulnerability is caused by an input validation error when handling the "HandwriterFilename" property in the "FileUploader.FUploadCtl.1" ActiveX control in FileUploader.dll. It allows remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
 
Impact
System Compromise: remote attackers can gain control of vulnerable systems.
 
Affected Products
Lycos FileUploader.dll 2.0 2
Aliases
Lycos.File.Upload.ActiveX.Access
References
http://www.securityfocus.com/bid/27411
http://www.frsirt.com/english/advisories/2008/0253
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0443
http://milw0rm.com/exploits/4967
Recommended Actions
Set the kill bit for CLSID "C36112BF-2FA3-4694-8603-3B510EA3B465".
See the Microsoft Knowledge Base Article below for details of the "kill bit" mechanism.
http://support.microsoft.com/kb/240797

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED