Skip to main content

Facebook Photo Uploader Control Remote Buffer Overflow Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 5 Feb 2008 4517 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Facebook Photo Uploader, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "ImageUploader4.ocx" ActiveX control when processing overly long arguments passed to certain methods or properties (e.g. "ExtractExif" or "ExtractIptc"), which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Facebook Photo Uploader version 4.5.57.0 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Facebook Photo Uploader version 4.5.57.1 :
http://upload.facebook.com/controls/FacebookPhotoUploader3.cab


Vulnerability Identifier

  • No CVE information is available

Source


Related Link