HTTP: BarCodeWiz Barcode LoadProperties ActiveX

This signature detects attempts to use unsafe ActiveX controls in BarCodeWiz Barcode. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

GetMySystem BarCodeWiz ActiveX control is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied input. An attacker may exploit this issue by enticing victims into opening a malicious webpage or HTML email that invokes the affected control. Successful exploits will allow attackers to execute arbitrary code within the context of the affected application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition. BarCodeWiz 3.29 is vulnerable to this issue; other versions may be affected as well.

Affected Products

Getmysystem barcodewiz

References

BugTraq: 54701 42097

CVE: CVE-2010-2932

Short Name
HTTP:STC:ACTIVEX:BARCODEWIZ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX BarCodeWiz Barcode CVE-2010-2932 LoadProperties bid:42097 bid:54701
Release Date
06/20/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3649
False Positive
Unknown
Vendors

Getmysystem

CVSS Score

9.3

Found a potential security threat?