|
|
|
|
| |
Credit:
The information has been provided by Andrea Micalizzi aka rgod.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-12-026/
|
| |
Vulnerable Systems:
* IBM SPSS
The specific flaw exists within the Render() method exposed by the ExportHTML.dll ActiveX control. This method causes a file to be written to an arbitrary path specified by the second argument (Output). The contents of the file can be controlled by manipulating the object members 'CssLocation', 'LayoutStyle' and 'EmbedCss'. The CssLocation member can be directed to a UNC path containing a file to be included in the file generated by the call to Render(). These behaviors can be exploited by an attacker to execute arbitrary code on the target system.
Vendor Status:
IBM has issued an update to correct this vulnerability
Patch Availability:
https://redmine/issues/11917
CVE Information:
CVE-2012-0190
Disclosure Timeline:
2011-07-20 - Vulnerability reported to vendor
2012-02-08 - Coordinated public release of advisory
|
|
|
|
|