|
|
|
![]() |
Vulnerability Note VU#210697Newtone ImageKit ActiveX buffer overflow vulnerabilitiesOverviewThe Newtone ImageKit ActiveX controls contain several buffer overflow vulnerabilities, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.I. DescriptionNewtone ImageKit is a set of ActiveX controls that provide image processing, scanning, and printing capabilities. The ActiveX controls provided by ImageKit contain several buffer overflow vulnerabilities.The vulnerable ImageKit controls are included with the CASIO Photo Loader software, which comes with CASIO digital cameras. Other software may also include the vulnerable controls.
{EF2E3685-201D-11D3-B1B0-00E0290EA3C9} {FF8676C3-11ED-11D3-B1B0-00E0290EA3C9}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{87CDBE22-FBF6-11D2-B1B0-00E0290EA3C9}] "Compatibility Flags"=dword:00000400 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EF2E3685-201D-11D3-B1B0-00E0290EA3C9}] "Compatibility Flags"=dword:00000400 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FF8676C3-11ED-11D3-B1B0-00E0290EA3C9}] "Compatibility Flags"=dword:00000400 Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the "Securing Your Web Browser" document. Systems Affected
Referenceshttp://www.cert.org/tech_tips/securing_browser/index.html#Internet_Explorer This vulnerability was reported by Will Dormann. Thanks to JPCERT/CC for coordinating the vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||