Denial of Service Condition in Compaq Presario Personal Computers

By utilizing the ActiveX control function LogDataListToFile, a malicious attacker can use a Web page to write a specified file to the system's hard drive, creating a potential Denial of Service (DoS) vulnerability.

Ken Pfeil

April 11, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedApril 11, 2001, by Compaq.

 

VERSION AFFECTED

  • Compaq Presario PCs running Windows Millennium Edition (Me) and Windows 98

DESCRIPTION


Compaqprovides customer support features through its Knowledge Center and Back Webcomponents for its Presario PCs running Windows Millennium Edition (Me) andWindows 98. Users use ActiveX to implement some of Presario's custom supportfeatures. By utilizing the ActiveX control function LogDataListToFile, amalicious attacker can use a Web page to write a specified file to the system'shard drive, creating a potential Denial of Service (DoS) vulnerability. Theintruder can't modify the content of the file, but can access the hardware andsoftware configuration information.

 

VENDOR RESPONSE

 

Thevendor, Compaq Computer Corporation, hasreleased Softpaq16629 to correct this vulnerability.

 

CREDIT


Discovered by Compaq.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like