Summary
This host is installed with Imera ImeraIEPlugin ActiveX and is prone to denial of service vulnerability.
Impact
Attacker may exploit this issue to download and execute arbitrary script code on the victim's system by passing malicious URLs and may crash the application.
Impact Level: System/Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, emove the product or replace the product by another one.
A workaround is to set the killbit for the CLSID {75CC8584-86D4-4A50-B976-AA72618322C6} http://support.microsoft.com/kb/240797
Insight
This issue is caused by errors in the ImeraIEPlugin.dll control while processing the URLs passed into DownloadProtocol, DownloadHost, DownloadPort and DownloadURI parameters.
Affected
Imera Systems ImeraIEPlugin.dll version 1.0.2.54 on Windows.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2009-0813 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Reader '.ETD File' Denial of Service Vulnerability (Mac OS X)
- 7-Zip Unspecified Archive Handling Vulnerability (Linux)
- Google Chrome Multiple Denial of Service Vulnerabilities - February 11(Linux)
- Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Mac OS X)
- Allegro Software RomPager 2.10 Denial of Service