Facebook Photo Uploader Control Remote Buffer Overflow Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Facebook Photo Uploader, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "ImageUploader4.ocx" ActiveX control when processing overly long arguments passed to certain methods or properties (e.g. "ExtractExif" or "ExtractIptc"), which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Facebook Photo Uploader version 4.5.57.0 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Facebook Photo Uploader version 4.5.57.1 :
http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with