PT-2006-5038 · Ibm · Ibm Access Support Egatherer
Derek Protas
+1
·
Publicado
2006-08-18
·
Atualizado
2018-10-17
·
CVE-2006-4221
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Access Support eGatherer versions prior to 3.20.0284.0
Description
The issue is related to a stack-based buffer overflow in the ActiveX control. This can be exploited by remote attackers to execute arbitrary code via a long
filename parameter to the RunEgatherer method.Recommendations
For versions prior to 3.20.0284.0, update to version 3.20.0284.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
RunEgatherer method to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Access Support Egatherer