|Main Archive Page > Month Archives > full-disclosure-uk archives|
Title : KSign KSignSWAT ActiveX Control Multiple Buffer Overflows Vulnerability
Version : AxKSignSWAT.dll (KSignSWAT ActiveX Control) ver. 220.127.116.11
Discoverer : KIM, KEE HONG (firstname.lastname@example.org)
Critical : High Critical
Test system : Windows XP SP2 Korean (All patched)
: Windows XP SP2 English (All patched)
Vendor : KSign (www.ksign.com)
Solution : patched. Note : 2007/05/14 notified KISA (Korean Information Security Agency) 2007/05/15 Confirmed Vulnerability 2007/05/21 Patched by Vendor (maybe...) 2007/05/22 Disclosure.
The KSign's KSignSWAT ActiveX is common certification solution if people use Internet banking, Goverment Sites and Stock Trading.
The KsignSWAT ActiveX has multiple buffer overflow vulnerability.
if uses HTML file which was crafted by this vulnerability, then you'll
KSignSWAT ActiveX has 5 vulnerable function. -SWAT_Init(), SWAT_InitEx(), SWAT_InitEX2(), SWAT_InitEx3(), SWAT_Login(). This functions requests several arguments (over the 2 arguments) and this functions didn't check argument buffer size.
It's a very simple buffer overflow enven Windows Environment.
POC CODE COMMING SOON Greet : BugTruck Group, PowerHacker Team (Thx, AmesianX) -- B.P.S _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/