Posted by Trancer on Oct 14 2008

Hewlett-PackardWrote a new Metaspoit exploit module for HP Mercury Quality Center ActiveX Control ProgColor Buffer Overflow vulnerability.

This module exploits a stack-based buffer overflow in SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 installed by TestDirector (TD) for Hewlett-Packard Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32. By setting an overly long value to ‘ProgColor’, an attacker can overrun a buffer and execute arbitrary code.

Download hpmqc_progcolor.rb.
Also on Metasploit.

References:
CVE-2007-1819
BID 23239
OSVDB 34317
iDefense Labs
HP Security Bulletin

Categories: Exploits, Metasploit

Leave a Reply


Follow Recognize-Security on Twitter