Vulnerability Description
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aurigma | Image Uploader Activex Control | 4.5.70.0 |
| All versions | ||
| Photouploader | 4.5.57.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2008/Feb/0023.html
- http://secunia.com/advisories/28707Vendor Advisory
- http://secunia.com/advisories/28713Vendor Advisory
- http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleI
- http://www.kb.cert.org/vuls/id/776931US Government Resource
- http://www.securityfocus.com/bid/27576
- http://www.securityfocus.com/bid/27577
- http://www.securitytracker.com/id?1019297
- http://www.vupen.com/english/advisories/2008/0391/references
- http://www.vupen.com/english/advisories/2008/0394/references
- https://www.exploit-db.com/exploits/5049
- http://seclists.org/fulldisclosure/2008/Feb/0023.html
- http://secunia.com/advisories/28707Vendor Advisory
- http://secunia.com/advisories/28713Vendor Advisory
- http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleI
FAQ
What is CVE-2008-0660?
CVE-2008-0660 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4...
How severe is CVE-2008-0660?
CVE-2008-0660 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0660?
Check the references section above for vendor advisories and patch information. Affected products include: Aurigma Image Uploader Activex Control, Facebook Facebook, Facebook Photouploader.