Description
Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method.
Affected products
- bluesky / blueskychat8.1.2.0
References
- MISChttp://www.securityfocus.com/archive/1/475150/100/0/threaded
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/35699
- MISChttp://www.securityfocus.com/bid/25149
- MAILING_LISThttp://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064995.html
- MISChttp://codeaudit.blogspot.com/
- VENDOR_ADVISORYhttp://www.vulnhunt.com/advisories/CAL-20070730-1_BlueSkyCat_v2.ocx_ActiveX_remote_heap_overflow_vulnerability_en.txt
- MISChttp://securityreason.com/securityalert/2959