NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


eBay Picture Manager Buffer Overflow

The vulnerability could have allowed for arbitrary code execution

By Marius Oiaga, Technology News Editor

7th of July 2006, 14:51 GMT

Adjust text size:


A new ActiveX vulnerability has been published yesterday. As is has become a sort of a tradition lately, the hole lies within the way in which ActiveX controls are integrated in the web page.
The exploitation of such a vulnerability will cause a buffer overflow on eBay's Picture Manager. The bug located in EPUImageControl object of the Picture Manager will, in the eventuality of an attack permit the execution of remote arbitrary code.

The vulnerability in eBay Picture Manager ActiveX control could allow an attacker to use a specially crafted HTML to trigger to buffer overflow in the EPUImageControl COM object in 'EUPWALcontrol.dll'. Such an attempt will let the target machine completely vulnerable to the execution of arbitrary code with the same privileges as the target user.

eBay Sell Your Item page was the only one that used the affected control, and the company was informed of the vulnerability and has stated that it already handled the situation and patched the vulnerability. As of that time an eBay customer using the ActiveX control will be advised to update the control.

A workaround to the problem is to disable the control by setting the kill bit on the following CSLID:
{4C39376E-FA9D-4349-BACC-D305C1750EF3}.
Read by 1,324 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.7/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


eBay Turns Ten. Happy Birthday!

Google to Roll-out PayPal Competitor

Sell, Bid and Buy on eBay with Opera Mini Mobile Browser

EBay Losses Ground and Executives

Phishing on PayPal

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM