| Release Date | Jan 29, 2008 |
| Severity | Critical |
| Impact | System Compromise: remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attempt to exploit a buffer overflow vulnerability in Lycos File Upload ActiveX control.
The vulnerability is caused by an input validation error when handling the "HandwriterFilename" property in the "FileUploader.FUploadCtl.1" ActiveX control in FileUploader.dll. It allows remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page. |
| Affected Products | Lycos FileUploader.dll 2.0 2 |
| Recommended Actions | Set the kill bit for CLSID "C36112BF-2FA3-4694-8603-3B510EA3B465". See the Microsoft Knowledge Base Article below for details of the "kill bit" mechanism. http://support.microsoft.com/kb/240797 |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0443
|
| Reference/s | http://www.securityfocus.com/bid/27411 (BugTraq) http://www.vupen.com/english/advisories/2008/0253 (FrSIRT) http://milw0rm.com/exploits/4967
|