J-Security Center

Title: Openwares.org Internet Explorer Patch Buffer Overflow Vulnerability

Severity: HIGH

Description:

Openwares.org is an organization that promotes open source web development and support tools. Openwares has released a patch to fix the Multiple Browser URI Display Obfuscation Weakness (BID 9182) in Microsoft Internet Explorer.

It has been reported that the Openwares Patch for Internet Explorer is prone to a buffer overflow vulnerability that may allow an attacker to execute arbitrary code on a vulnerable system in order to gain unauthorized access. The condition is present due to insufficient boundary checking.

The problem is reported to exist in the BeforeNavigateEvent() function of IETray.cpp module. It has been reported that a URL is copied to a buffer limited to 256 bytes. Supplying a longer URL could possibly overflow an affected buffer on the stack. This may cause a denial of service condition in Internet Explorer.

An attacker may leverage the issue by exploiting an unbounded memory copy operation to overwrite the saved return address/base pointer, causing an affected procedure to return to an address of their choice. Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the vulnerable software in order to gain unauthorized access.

Affected Products:

  • Openwares.org IEpatch 0.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.