BaiduX.UiCheck.ActiveX.GetUiDllVersion

NameBaiduX.UiCheck.ActiveX.GetUiDllVersion.Method.Access
Release DateJan 05, 2010
SeverityCritical
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in BaiduX.

The vulnerability is caused by an error when the GetUiDllVersion function in an ActiveX control in UiCheck.dll handles a specially crafted filename parameter. It allows a remote attacker to execute arbitrary code.
Affected ProductsBaiduX
Recommended ActionsUpgrade to the latest version:
http://v.baidu.com/xiaba/index.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2970
Reference/shttp://www.vupen.com/english/advisories/2009/2962 (FrSIRT)
Reference: VID-17857