GOM Player GomWebCtrl.GomManager.1 ActiveX control buffer overflow

gomplayer-gomwebctrl-bo (38159) The risk level is classified as HighHigh Risk

Description:

The GOM Player GomWebCtrl.GomManager.1 ActiveX control (GomWeb3.dll) is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long argument to the OpenURL() method, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the user or cause the victim's browser to crash.

Platforms Affected:

  • GRETECH, GOM Player 2.1.6.3499

Remedy:

Upgrade to the latest version of GOM Player (2.1.8.3682 or later), available from the GOM PLAYER Web site. See References.

Consequences:

Gain Access

References:

  • GOM PLAYER Web site, GOM PLAYER at http://www.gomplayer.com/main.html.
  • BID-26236: Gretech GOM Player GomWeb3.DLL Remote Buffer Overflow Vulnerability
  • CVE-2007-5779: Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.
  • SA27418: GOM Player GOM Manager ActiveX Control Buffer Overflow
  • VUPEN/ADV-2007-3634: GOM Player GomWeb3 ActiveX Control Buffer Overflow Vulnerability

Reported:

Oct 29, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page