Editor Login | Register
Ekle

> World > Security
HP Software update HPeDiag ActiveX Control Insecure Methods and Buffer overflow - Security - World -
CWRedLight
(Date : 27.04.2008 16:23:33)
%10


HP Software update HPeDiag ActiveX Control Insecure Methods and Buffer overflow
Description:
Some vulnerabilities have been reported in HP Software Update, which can be exploited by malicious people to disclose certain information or compromise a vulnerable system.

1) A boundary error in the HPeSupportDiags.HPIniFileUtil.1 ActiveX control (HPeDiag.dll) when handling the "GetXmlFromIni()" method can be exploited to cause a stack-based buffer overflow.

Successful exploitation allows execution of arbitrary code.

2) Insecure methods in certain ActiveX controls (e.g. HPeSupportDiags.HPRegUtil.1, HPeSupportDiags.HPFileUtil.1, HPeSupportDiags.HPSystemBoardInfo.1, HPeSupportDiags.HPOperatingSystem.1) can be exploited to e.g. read registry entries, read text files, or retrieve system and OS information.

The vulnerabilities are reported in versions 4.000.009.002 and prior.

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.

Solution:
Update to version 4.000.010.008 (see vendor"s advisory for details).

Provided and/or discovered by:
Tan Chew Keong

Changelog:
2008-04-25: Updated advisory based on additional information from Tan Chew Keong.

Original Advisory:
HPSBGN02333 SSRT080031:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01439758
Secunia Advisory: SA29966  
Release Date: 2008-04-25

Critical:
Highly critical
Impact: Exposure of system information
Exposure of sensitive information
System access
Where: From remote
Solution Status: Vendor Patch

Software:HP Software Update 3.x
HP Software Update 4.x

CVE reference:CVE-2008-0712 (Secunia mirror)




Derecelendir
Kaynak http://secunia.com/advisories/29966/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS