Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft TSAC ActiveX Control Buffer Overflow Vulnerability

Solution:
The MSIE cumulative update described in MS02-047 sets the "kill bit" for the TSAC control. Applying this update will effectively eliminate this vulnerability.

The update is available at:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms02-047.asp

To set the "kill-bit" manually, see knowledgebase article Q240797. The "kill-bit" should be set for the following IDs:

{1fb464c8-09bb-4017-a2f5-eb742f04392f}
{791fa017-2de3-492e-acc5-53c67a2b94d0}

Microsoft has released a new version of the control that is not vulnerable:


Microsoft TSAC ActiveX Control







 

Privacy Statement
Copyright 2009, SecurityFocus