HTTP: MW6 Barcode Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in MW6 Barcode (Barcode.dll). An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

MW6 Technologies Barcode ActiveX control is prone to a heap-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed attacks will likely cause denial-of-service conditions.

Affected Products

Mw6_technologies barcode_activex

References

BugTraq: 33451

CVE: CVE-2009-0298

Short Name
HTTP:STC:ACTIVEX:MW6-BARCODE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX Barcode CVE-2009-0298 Control MW6 Unsafe bid:33451
Release Date
08/27/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Mw6_technologies

CVSS Score

9.3

Found a potential security threat?