|
|
Family: Windows --> Category: infos
I-Nav ActiveX Buffer Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks version of I-Nav ActiveX control
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote Windows host has an ActiveX control that is affected by a
buffer overflow vulnerability.
Description :
The remote host contains an ActiveX control, 'VUpdater.Install',
associated with Verisign I-Nav, which provides support for
Internationalized Domain Names in Microsoft Internet Explorer, Outlook
and Outlook Express that reportedly contains a buffer overflow
vulnerability that arises when processing CAB files. A remote
attacker may be able to leverage this issue to specify an arbitrary
executable to be run subject to the rights of the current user.
See also :
http://www.zerodayinitiative.com/advisories/ZDI-06-014.html
http://www.idnnow.com/
Solution :
Download the latest version of the software from the vendor.
Threat Level:
Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:N/I:P/A:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|