[NT] WildTangent Web Driver Long Filename Stack Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 06/03/04

  • Next message: SecuriTeam: "[NT] Mollensoft FTP Server CD Buffer Overflow"
    To: list@securiteam.com
    Date: 3 Jun 2004 17:05:23 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      WildTangent Web Driver Long Filename Stack Overflow
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.wildtangent.com> WildTangent "provide high quality
    interactive media technology to the Internet in the form of their
    WebDriver. This is used by some of the largest companies and corporations
    world-wide to provide advanced media content to over 80 million users of
    their Internet plug-in". A buffer overflow in the product allows a web
    site to cause arbitrary remote code execution on the target system.

    DETAILS

    It is possible to cause a number of buffer overruns within the WildTangent
    package, namely within the WTHoster and WebDriver modules, via any method
    which takes a filename as a parameter. During the process of constructing
    an absolute path for this file, a concatenation of a predefined directory
    path and the filename supplied as a parameter occurs through an unchecked
    call to strcat(). This can easily be made to overflow the buffer and can
    allow arbitrary remote code execution on the target system.

    A working exploit has been created and tested against a vulnerable system,
    and as such it is highly recommended that users of the WildTangent plug-in
    install the updated version immediately.

    Fix Information:
    WebDriver 4.1 has been released to protect against the vulnerability. This
    can be obtained from the WildTangent website at the address below:
    <http://www.wildtangent.com/default.asp?pageID=webdriver_download>
    http://www.wildtangent.com/default.asp?pageID=webdriver_download.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:peter@ngssoftware.com> Peter
    Winter-Smith.
    The original article can be found at:
    <http://www.ngssoftware.com/advisories/wildtangent.txt>
    http://www.ngssoftware.com/advisories/wildtangent.txt.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Mollensoft FTP Server CD Buffer Overflow"

    Relevant Pages

    • [NT] Microsoft Windows NTFS Improper Handler Closing
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... from a system shutdown, uninitialized data may be visible in files from ...
      (Securiteam)
    • [NT] Cross Application Scripting in Trend Micros Antivirus Software
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The SecuriTeam alerts list - Free, Accurate, Independent. ... When the product alerts the user of a possible virus, it creates an HTML ...
      (Securiteam)
    • [TOOL] tcpstatflow - Covert Tunnel Detector
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... For example, he could set up a SSH server on the Internet, listening port ... one way and the opposite (within a single TCP connection). ...
      (Securiteam)
    • [EXPL] Eudora Attachment Spoof Exploit Revisited
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... present in the newest release of Eudora. ... Can be exploited if there is more than one way into attach: in my setup ...
      (Securiteam)
    • [UNIX] Phorum SQL Injection (userlogin.php)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... An SQL injection vulnerability exists in the 'userlogin.php' script. ... the MD5 hash of the user one character at a time. ...
      (Securiteam)