Threat Monitor
Troj.Exploit.JS.Agent.avl
| Aliases: | |
|---|---|
| Pattern: | 201007301330 |
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
|---|---|---|---|
|
|
|
|
GlobalLink is prone to a heap-based buffer overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
The issue occurs in the SetClientInfo() function in the glitemflat.dll ActiveX control with the CLSID:7D1425D4-E2FC-4A52-BDA9-B9DCAC5EF574. By persuading a victim to view a specially-crafted Web page, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the browser to crash.
Affected: GlobalLink GlobalLink 2.7.0.8
The issue occurs in the SetClientInfo() function in the glitemflat.dll ActiveX control with the CLSID:7D1425D4-E2FC-4A52-BDA9-B9DCAC5EF574. By persuading a victim to view a specially-crafted Web page, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the browser to crash.
Affected: GlobalLink GlobalLink 2.7.0.8


