Description
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. NOTE: some of these details are obtained from third party information. NOTE: the researcher claims that this is the same as CVE-2007-5108, but there is insufficient detail for CVE-2007-5108 to be certain.
Affected products
- ask.com / ask_toolbar4.0.2.53
References
- EXPLOIThttps://www.exploit-db.com/exploits/4452
- MISChttp://www.foxitsoftware.com/pdf/reader/security.htm
- MISChttp://www.securityfocus.com/archive/1/480459/100/0/threaded
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/3265
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/36757
- VENDOR_ADVISORYhttp://secunia.com/advisories/26960
- MISChttp://www.securityfocus.com/bid/25785