codeaudit.blogspot.com
http://codeaudit.blogspot.com/ CVE-2007-4145
BlueSkyChat ActiveX Control 8.1.2 - Remote Buffer Overflow
Record summary
CVE-2007-4145 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBlueSkyChat ActiveX Control 8.1.2 - Remote Buffer OverflowExploitDB exploitby Code Audit LabsNot analyzed1 file
References
820070731 CAL-20070730-1 BlueSkyCat ActiveX Remote Heap Overflow vulnerabilitymailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064995.html 2959Third-party advisory
http://securityreason.com/securityalert/2959 20070731 CAL-20070730-1 BlueSkyCat ActiveX Remote Heap Overflow vulnerabilitymailing list
http://www.securityfocus.com/archive/1/475150/100/0/threaded 25149vdb entry
http://www.securityfocus.com/bid/25149 vulnhunt.com
http://www.vulnhunt.com/advisories/CAL-20070730-1_BlueSkyCat_v2.ocx_ActiveX_remote_heap_overflow_vulnerability_en.txt blueskychat-v2-bo(35699)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35699 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4145