GOM Player GomWebCtrl.GomManager.1 ActiveX control buffer overflow
| gomplayer-gomwebctrl-bo (38159) |
Description:
The GOM Player GomWebCtrl.GomManager.1 ActiveX control (GomWeb3.dll) is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long argument to the OpenURL() method, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the user or cause the victim's browser to crash.
Platforms Affected:
- GRETECH, GOM Player 2.1.6.3499
Remedy:
Upgrade to the latest version of GOM Player (2.1.8.3682 or later), available from the GOM PLAYER Web site. See References.
Consequences:
Gain Access
References:
- GOM PLAYER Web site, GOM PLAYER at http://www.gomplayer.com/main.html.
- BID-26236: Gretech GOM Player GomWeb3.DLL Remote Buffer Overflow Vulnerability
- CVE-2007-5779: Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.
- SA27418: GOM Player GOM Manager ActiveX Control Buffer Overflow
- VUPEN/ADV-2007-3634: GOM Player GomWeb3 ActiveX Control Buffer Overflow Vulnerability
Reported:
Oct 29, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
