CVE-2009-2495
HP Security Bulletin HPSBMA02488 SSRT100013
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
La Active Template Library (ATL) en Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 y 2008 Gold y SP1, y Visual C++ 2005 SP1 y 2008 Gold y SP1 no cumple adecuadamente con la terminación de cadena, lo que permite a atacantes remotos obtener información sensible a través de un documentos HTML manipulado con un (1) control o (2) componente ATL que provoca un desbordamiento de lectura de búfer. Relacionado con la reserva de cabeceras y búfers ATL. También conocida como "Vulnerabilidad de cadena nula ATL".
Remote exploitation of an information disclosure vulnerability in Microsoft's ATL/MFC ActiveX template, as included in various vendor's ActiveX controls, allows attackers to read memory contents within Internet Explorer. iDefense has confirmed the existence of this vulnerability inside Microsoft's ATL version 9.0. Any source code compiled with these libraries may also be vulnerable. Previous versions may also be affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-17 CVE Reserved
- 2009-07-29 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/35967 | Third Party Advisory | |
http://secunia.com/advisories/36374 | Third Party Advisory | |
http://secunia.com/advisories/36746 | Third Party Advisory | |
http://www.adobe.com/support/security/bulletins/apsb09-10.html | X_refsource_confirm | |
http://www.adobe.com/support/security/bulletins/apsb09-13.html | X_refsource_confirm | |
http://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1 | X_refsource_confirm | |
http://www.us-cert.gov/cas/techalerts/TA09-195A.html | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA09-286A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2009/2034 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6305 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6478 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7573 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Visual C\+\+ Search vendor "Microsoft" for product "Visual C\+\+" | 2005 Search vendor "Microsoft" for product "Visual C\+\+" and version "2005" | sp1_redistribution_pkg |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual C\+\+ Search vendor "Microsoft" for product "Visual C\+\+" | 2008 Search vendor "Microsoft" for product "Visual C\+\+" and version "2008" | redistribution_pkg |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual C\+\+ Search vendor "Microsoft" for product "Visual C\+\+" | 2008 Search vendor "Microsoft" for product "Visual C\+\+" and version "2008" | sp1_redistribution_pkg |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio Search vendor "Microsoft" for product "Visual Studio" | 2005 Search vendor "Microsoft" for product "Visual Studio" and version "2005" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio Search vendor "Microsoft" for product "Visual Studio" | 2005 Search vendor "Microsoft" for product "Visual Studio" and version "2005" | sp1, 64_bit_hosted_visual_c\+\+_tools |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio Search vendor "Microsoft" for product "Visual Studio" | 2008 Search vendor "Microsoft" for product "Visual Studio" and version "2008" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio Search vendor "Microsoft" for product "Visual Studio" | 2008 Search vendor "Microsoft" for product "Visual Studio" and version "2008" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Visual Studio .net Search vendor "Microsoft" for product "Visual Studio .net" | 2003 Search vendor "Microsoft" for product "Visual Studio .net" and version "2003" | sp1 |
Affected
|