Short Name |
HTTP:STC:ACTIVEX:LEADTOOLS |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
LEADTOOLS Imaging ActiveX Control Memory Corruption |
Release Date |
2010/11/10 |
Update Number |
1812 |
Supported Platforms |
idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to use unsafe ActiveX controls in LEADTOOLS Imaging solution. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
LEADTOOLS Imaging Common Dialogs ActiveX control is prone to multiple memory-corruption vulnerabilities including multiple integer-overflow vulnerabilities and multiple buffer-overflow vulnerabilities. An attacker may exploit these issues to execute arbitrary code within the context of the application (typically Internet Explorer) that invoked the ActiveX control. Failed exploit attempts will result in a denial-of-service condition. LEADTOOLS Imaging Common Dialogs 16.5 is vulnerable; other versions may also be affected.