Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer Plugin.OCX Load() Method Buffer Overflow Vulnerability

Microsoft Internet Explorer 'plugin.ocx' has been reported prone to a buffer overflow in some configurational circumstances.

It has been reported that due to insufficient bounds checking performed on the Load() method that can be supplied by a third-party file type, an attacker may overrun a buffer and cause arbitrary code to be executed. The code is executed when a malicious URL to a third-party file is followed.

Exploitation of this issue is dependant on a third-party Internet Explorer plugin being installed on the vulnerable system.

Reports indicate that this vulnerability is actually a heap overflow in plugin.ocx.

This issue was described in BID 7417 and is now being assigned a separate BID.

Microsoft initially reported this vulnerability as a single issue within Plugin.ocx, however, there are in fact two separate issues that were fixed. The other vulnerability is described in BID 7491.







 

Privacy Statement
Copyright 2008, SecurityFocus