SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  WildTangent Web Driver Vendors:  WildTangent, Inc.
WildTangent Web Driver Buffer Overflows in WTHoster and WebDriver Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1010323
SecurityTracker URL:  http://securitytracker.com/id?1010323
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  May 28 2004
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  NGSSoftware
Version(s): WildTangent Web Driver 4.0
Description:  A stack overflow vulnerability was reported in WildTangent Web Driver. A remote user can execute arbitrary code on the target system.

Peter Winter-Smith of NGSSoftware reported that there are several buffer overflows in the WTHoster and WebDriver modules. A remote user can reportedly supply a specially crafted filename to trigger the overflow and execute arbitrary code on the target system.

The vendor was reportedly notified on March 31, 2004.

Impact:  A remote user can execute arbitrary code on the target system.
Solution:  The vendor has released a fixed version (4.1), available at:

http://www.wildtangent.com/default.asp?pageID=webdriver_download

Vendor URL:  www.wildtangent.com/ (Links to External Site)
Cause:  Boundary error
Underlying OS:  Windows (Any)
Reported By:  "NGSSoftware Insight Security Research" <nisr@ngssoftware.com>
Message History:   None.


 Source Message Contents

Date:  Thu, 27 May 2004 13:13:10 +0100
From:  "NGSSoftware Insight Security Research" <nisr@ngssoftware.com>
Subject:  WildTangent Web Driver Long FileName Stack Overflow

 

NGSSoftware Insight Security Research Advisory

Name: WildTangent Web Driver Long FileName Stack Overflow
Systems Affected: WildTangent Web Driver 4.0 (earlier versions not tested)
Severity: High
Vendor URL: http://www.wildtangent.com
Author: Peter Winter-Smith [ peter@ngssoftware.com ]
Date Vendor Notified:    31th March 2004
Date of Public Advisory: 27th May 2004
Advisory number: #NISR27052004
Advisory URL: http://www.ngssoftware.com/advisories/wildtangent.txt


Description
***********

WildTangent provide high quality interactive media technology to the
Internet in the form of their WebDriver. This is used by some of the
largest companies and corporations world-wide to provide advanced media
content to over 80 million users of their Internet plug-in.


Details
*******

It is possible to cause a number of buffer overruns within the WildTangent
package, namely within the WTHoster and WebDriver modules, via any method
which takes a filename as an parameter. During the process of constructing
an absolute path for this file, a concatenation of a predefined directory
path and the filename supplied as a parameter occurs through an unchecked
call to strcat(). This can easily be made to overflow the buffer and can
allow arbitrary remote code execution on the target system.

A working exploit has been created and tested against a vulnerable system,
and as such it is highly recommended that users of the WildTangent plug-in
install the updated version immediately.


Fix Information
***************

WebDriver 4.1 has been released to protect against the vulnerability. This
can be obtained from the WildTangent website at the address below:

http://www.wildtangent.com/default.asp?pageID=webdriver_download


A check for this vulnerability has been added to Typhon III, NGSSoftware's
advanced vulnerability assessment scanner. For more information please
visit the NGSSoftware website at http://www.ngssoftware.com/


About NGSSoftware
*****************

NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware
have offices in the South of London and the East Coast of Scotland.
NGSSoftware's sister company NGSConsulting, offers best of breed security
consulting services, specialising in application, host and network
security assessments.

http://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC