|
|
Zoomify Viewer ActiveX Control Multiple Remote Command Execution Vulnerabilities
|
Multiple vulnerabilities have been identified in Zoomify Viewer ActiveX Control, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by buffer overflow errors in the "ZActiveX.dll" module when processing a malformed property or method, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Zoomify Viewer ActiveX Control
The vendor recommends switching to the Flash-based viewing solutions.
Set a kill bit for the CLSID {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB}.
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/2142 http://www.kb.cert.org/vuls/id/174177
Vulnerability reported by Will Dormann (CERT/CC).
2007-06-12 : Initial release
2007-06-13 : Updated Solution
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|