Denial of Service Condition in Compaq Presario Personal Computers
By utilizing the ActiveX control function LogDataListToFile, a malicious attacker can use a Web page to write a specified file to the system's hard drive, creating a potential Denial of Service (DoS) vulnerability.
April 11, 2001
ReportedApril 11, 2001, by Compaq.
VERSION AFFECTED
Compaq Presario PCs running Windows Millennium Edition (Me) and Windows 98
DESCRIPTION
Compaqprovides customer support features through its Knowledge Center and Back Webcomponents for its Presario PCs running Windows Millennium Edition (Me) andWindows 98. Users use ActiveX to implement some of Presario's custom supportfeatures. By utilizing the ActiveX control function LogDataListToFile, amalicious attacker can use a Web page to write a specified file to the system'shard drive, creating a potential Denial of Service (DoS) vulnerability. Theintruder can't modify the content of the file, but can access the hardware andsoftware configuration information.
VENDOR RESPONSE
Thevendor, Compaq Computer Corporation, hasreleased Softpaq16629 to correct this vulnerability.
CREDIT
Discovered by Compaq.
About the Author
You May Also Like