Update Protection against Microsoft Windows MFC Library FileFind Class Heap Overflow Vulnerability
| Check Point Reference: | CPAI-2007-128 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA26800 | |
| Industry Reference(s): | CVE-2007-4916 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? HP All-in-One Series Web Release HP Photo & Imaging Gallery 1.1 Microsoft Windows XP Microsoft Windows 2000 Microsoft Windows 2003 Microsoft Visual Studio 2005 Microsoft Visual Studio 6.0 Microsoft Visual Studio .NET | ||
| Vulnerability Description A buffer overflow vulnerability exists in Microsoft Windows MFC shared library. The Microsoft Foundation Class Library is a library that wraps portions of the Windows API in C++ classes, including functionality that enables them to use a default application framework. By convincing a user to visit a specially crafted Web page, a remote attacker may trigger this vulnerability to execute arbitrary code on an affected system. |
||
|
Vulnerability Details The vulnerability is due to an error in the FileFind Class that can be exploited via applications that use the FileFind class and pass user provided data to the affected function. To trigger this issue, an attacker may create a malicious web page that will exploit this vulnerability through an ActiveX control provided by HP All-in-One and HP Photo & Imaging Gallery products. Successful exploitation may allow execution of arbitrary code on the vulnerable system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the vulnerable ActiveX Control. Depending on the traffic mix, activating this protection may result in performance degradation.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The update released on November 7, 2007 includes the following protections:
Microsoft Windows Media Player Skin Parsing Vulnerability (MS07-047) CPAI-2007-102
MIT Kerberos kadmind RPC Library Buffer Overflow Vulnerability (CPAI-2007-126)
Sun Microsystems JRE Memory Exception Vulnerability (CPAI-2007-127)
Microsoft Windows MFC Library Heap Overflow Vulnerability (CPAI-2007-128)
Protections against Recent Malware Threats (CPAI-2007-129)