Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 07:48:41 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2262253200&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Ffiledesc%2Fwebex_ucf_newobject.rb.txt.html%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2262253200.1338191321.1338191321.1338191321.1%3B%2B__utmz%3D32867617.1338191321.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow http://packetstormsecurity.org/files/86895/webex_ucf_newobject.rb.txt http://packetstormsecurity.org/files/86895/webex_ucf_newobject.rb.txt http://packetstormsecurity.org/files/86895/WebEx-UCF-atucfobj.dll-ActiveX-NewObject-Method-Buffer-Overflow.html Thu, 04 Mar 2010 23:34:42 GMT This Metasploit module exploits a stack-based buffer overflow in WebEx's WebexUCFObject ActiveX Control. If an long string is passed to the 'NewObject' method, a stack- based buffer overflow will occur when copying attacker-supplied data using the sprintf function. It is noteworthy that this vulnerability was discovered and reported by multiple independent researchers.