vendor:
DiViS-Web DVR System
by:
Digital Security Research Group [DSecRG]
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: DiViS-Web DVR System
Affected Version From: 3.0.0.7
Affected Version To: 3.0.0.7
Patch Exists: NO
Related CWE: N/A
CPE: a:chance-i:divis-web_dvr_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web
2009
DSECRG-09-035
DiViS-Web ActiveX (ActiveView.cab) has Heap Overflow vulnerability. Heap overflow vulnerability found in AddSiteEx() function. There is an exploitable heap overflow vulnerability in DVR's ActiveX control (ActiveView.cab). If an DVR user were to visit a malicious web page, the overflow could be triggered allowing for a 'remote' compromise of the user's machine. Alternatively, an attacker could send their target a specially crafted e-mail, loaded with an exploit to take advantage of this vulnerability. The problem arises by passing an overly long string to the AddSiteEx method of the control.
Mitigation:
NONE