[external image: Posted Image]This vulnerability report for Ask Toolbar 4.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.
Secunia Advisory
- Secunia Advisory: SA26960
- Release Date: 2007-09-25
- Last Update: 2007-09-28
- Critical: Highly critical
- Impact: System access
- Where: From remote
- Solution Status: Unpatched
SecuniaJoey Mengele has discovered a vulnerability in Ask Toolbar, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control (askBar.dll) when handling the "ShortFormat" property. This can be exploited to cause a stack-based buffer overflow by assigning an overly long (greater than 500 bytes) string to the affected property.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 4.0.2. Other versions may also be affected.
Source: Corrine @ Security Garden
Reason for posting this?
See BillP, Developer Of WinPatrol Won't Sell Out, Zone Alarms Unwanted But 'Installed-By-Default' Toolbar and Well, this is interesting