NGSSoftware Insight Security Research Advisory Name: WildTangent Web Driver Long FileName Stack Overflow Systems Affected: WildTangent Web Driver 4.0 (earlier versions not tested) Severity: High Vendor URL: http://www.wildtangent.com Author: Peter Winter-Smith [ peter@xxxxxxxxxxxxxxx ] Date Vendor Notified: 31th March 2004 Date of Public Advisory: 27th May 2004 Advisory number: #NISR27052004 Advisory URL: http://www.ngssoftware.com/advisories/wildtangent.txt Description *********** WildTangent provide high quality interactive media technology to the Internet in the form of their WebDriver. This is used by some of the largest companies and corporations world-wide to provide advanced media content to over 80 million users of their Internet plug-in. Details ******* It is possible to cause a number of buffer overruns within the WildTangent package, namely within the WTHoster and WebDriver modules, via any method which takes a filename as an parameter. During the process of constructing an absolute path for this file, a concatenation of a predefined directory path and the filename supplied as a parameter occurs through an unchecked call to strcat(). This can easily be made to overflow the buffer and can allow arbitrary remote code execution on the target system. A working exploit has been created and tested against a vulnerable system, and as such it is highly recommended that users of the WildTangent plug-in install the updated version immediately. Fix Information *************** WebDriver 4.1 has been released to protect against the vulnerability. This can be obtained from the WildTangent website at the address below: http://www.wildtangent.com/default.asp?pageID=webdriver_download A check for this vulnerability has been added to Typhon III, NGSSoftware's advanced vulnerability assessment scanner. For more information please visit the NGSSoftware website at http://www.ngssoftware.com/ About NGSSoftware ***************** NGSSoftware design, research and develop intelligent, advanced application security assessment scanners. Based in the United Kingdom, NGSSoftware have offices in the South of London and the East Coast of Scotland. NGSSoftware's sister company NGSConsulting, offers best of breed security consulting services, specialising in application, host and network security assessments. http://www.ngssoftware.com/ Telephone +44 208 401 0070 Fax +44 208 401 0076 enquiries@xxxxxxxxxxxxxxx