1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP Learn2 Strunner ActiveX BO

HTTP Learn2 Strunner ActiveX BO

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempt to exploit a buffer overflow vulnerability by passing long arguments into a method of Learn2 Strunner ActiveX Control.

Additional Information

Learn2 STRunner is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.

An attacker can exploit these issues to execute arbitrary code within the context of application that invoked the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.

Affected

  • Learn2 STRunner 0

Response

Download and install all vendor patches related to this issue.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube