HTTP: BaoFeng Storm Unsafe ActiveX Buffer Overflow

This signature detects attempts to use unsafe ActiveX controls in BaoFeng Storm. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

BaoFeng Storm ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.

Affected Products

Baofeng storm

References

BugTraq: 25601 34869 29274 34789

CVE: CVE-2009-1807

Short Name
HTTP:STC:ACTIVEX:BAOFENG-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX BaoFeng Buffer CVE-2009-1807 Overflow Storm Unsafe bid:25601 bid:29274 bid:34789 bid:34869
Release Date
09/02/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Baofeng

CVSS Score

9.3

Found a potential security threat?