Twitter iPhone pliant OnePlus 11 PS5 Disney+ Orange Livebox Windows 11

RAV online

2 réponses
Avatar
JacK
Hello,

On en parlait dernièrement : les AV online utilisant un activeX ...

RAV Online Scanning ActiveX Buffer Overflow
------------------------------------------------------------------------


SUMMARY

<http://www.ravantivirus.com/index.php> RAV Online Scanning is "a free
antivirus scanner for internet users. It is run on the user's browsers as
an ActiveX".

The ActiveX file called ravonline.dll has a function named
browseForFolder() that can be overflowed by passing a very long string as
an argument. Since the function browseForFolder() is imported from
Shell32.dll, so it looks like the problem maybe lay in the Shell32.dll and
not in the ActiveX itself however users that use RAV Online Scanning are
still vulnerable to the overflow.

DETAILS

Workaround:
Delete the ActiveX (ravonline.dll) in the "Downloaded Program Files" in
your Windows Directory.

Vendor status:
The vendor has been notified of the issue, no response have been received
until now.


ADDITIONAL INFORMATION

The information has been provided by <mailto:trihuynh@zeeup.com> Tri
Huynh.
--
JacK

2 réponses

Avatar
Brain 0verride
Le Sun, 20 Jul 2003 20:16:16 +0200, JacK a écrit :

Hello,

On en parlait dernièrement : les AV online utilisant un activeX ...


Quand je disais que ca pue les activex ;)

amicalement,

--
Christophe Casalegno | Digital Network | UIN : 153305055
http://www.digital-network.net | http://www.speed-connect.com
http://www.securite-reseaux.com | http://www.dnsi.info
Security engineer network/systems | Intrusion tests specialist.

Avatar
Roland Garcia

On en parlait dernièrement : les AV online utilisant un activeX ...

RAV Online Scanning ActiveX Buffer Overflow
------------------------------------------------------------------------


SUMMARY

<http://www.ravantivirus.com/index.php> RAV Online Scanning is "a free
antivirus scanner for internet users. It is run on the user's browsers as
an ActiveX".

The ActiveX file called ravonline.dll has a function named
browseForFolder() that can be overflowed by passing a very long string as
an argument. Since the function browseForFolder() is imported from
Shell32.dll, so it looks like the problem maybe lay in the Shell32.dll and
not in the ActiveX itself however users that use RAV Online Scanning are
still vulnerable to the overflow.


Le propriétaire de RAV devrait le signaler à Microsoft :-D

Roland Garcia