This application requires Javascript for optimal performance.

BaiduX.UiCheck.ActiveX.GetUiDllVersion.Method.Access

Release Date

Jan 05, 2010

Severity

critical

Impact

System Compromise

Description

This indicates an attack attempt against a buffer-overflow vulnerability in BaiduX.

The vulnerability is caused by an error when the GetUiDllVersion function in an ActiveX control in UiCheck.dll handles a specially crafted filename parameter. It allows a remote attacker to execute arbitrary code.

Affected Products

BaiduX

Recommended Actions

Upgrade to the latest version:
http://v.baidu.com/xiaba/index.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2970

Reference/s

http://www.frsirt.com/english/advisories/2009/2962 (FrSIRT)

Reference: VID-17857