PDA

View Full Version : iMesh IMWebControl Class Heap Overflow



newsbot
18-12-2007, 10:40 PM
iMesh is "a file sharing and online social network. It uses a proprietary, centralized, P2P protocol. iMesh is owned by an American company iMesh, Inc. and maintains a development center in Israel". A vulnerability in the iMesh ActiveX allows attackers to cause it to overflow a heap buffer allocated to the product which in turn can be used to execute arbitrary code.

http://www.securiteam.com/windowsntfocus/6N00B2AKKU.html