Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-0647

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-0647
Last Modified 07 Mar 2011 10:05:02
Published 07 Feb 2008 04:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-0647

Summary

Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Ourgame.com Glworld 2.6.1.29

  • Ourgame.com Hangameplugincn18 Activex Control


References

VUPEN - ADV-2008-0427

MISC - http://www.symantec.com/enterprise/security_response/weblog/2008/02/zeroday_exploit_for_lianzong_g.html

SECUNIA - 28809

BID - 27626

MILW0RM - 5153


Last Updated: 27 May 2016 10:46:52