SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#29795

HHOpen ActiveX Control buffer overflow in OpenHelp method

Overview

I. Description

The HHOpen ActiveX control (hhopen.ocx) has a buffer overflow in the OpenHelp method. Because the control is marked safe-for-scripting, an attacker may be able to script this control and exploit the vulnerability when you visit a web page.

The classID for the vulnerable control is: {130D7743-5F5A-11D1-B676-00A0C9697233}.

II. Impact

An attacker may be able to exploit a buffer overflow in the HHOpen ActiveX control and execute arbitrary code on the system of the person visiting a malicious web page.

III. Solution

Apply a patch

Apply the patch provided by Microsoft in Security Bulletin MS99-037. This patch sets the kill bit which prevents the control from being loaded by Internet Explorer.

Disable "Script ActiveX controls marked safe for scripting"

In your Internet Explorer security settings, set this option to "disable" or "prompt".

Systems Affected

VendorStatusDate NotifiedDate Updated
MicrosoftVulnerable31-Oct-2000

References


http://www.microsoft.com/technet/security/bulletin/ms99-037.asp
http://www.microsoft.com/technet/security/bulletin/fq99-037.asp
http://home.ntware.com/bugs/activex_bug__5.html

Credit

This document was written by Cory F Cohen.

Other Information

Date Public:99-09-10
Date First Published:2000-10-31
Date Last Updated:2000-11-01
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:12.66
Document Revision:8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2000 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader