Vulnerability Note VU#29795
HHOpen ActiveX Control buffer overflow in OpenHelp method
Overview
Description
The HHOpen ActiveX control (hhopen.ocx) has a buffer overflow in the OpenHelp method. Because the control is marked safe-for-scripting, an attacker may be able to script this control and exploit the vulnerability when you visit a web page. The classID for the vulnerable control is: {130D7743-5F5A-11D1-B676-00A0C9697233}. |
Impact
An attacker may be able to exploit a buffer overflow in the HHOpen ActiveX control and execute arbitrary code on the system of the person visiting a malicious web page. |
Solution
Apply a patch |
Disable "Script ActiveX controls marked safe for scripting" |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft | Vulnerable | - | 20 Apr 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/bulletin/ms99-037.asp
- http://www.microsoft.com/technet/security/bulletin/fq99-037.asp
- http://home.ntware.com/bugs/activex_bug__5.html
Credit
This document was written by Cory F Cohen.
Other Information
- CVE IDs: Unknown
- Date Public: 10 Sep 99
- Date First Published: 31 Oct 2000
- Date Last Updated: 01 Nov 2000
- Severity Metric: 12.66
- Document Revision: 8
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify