PT-2007-3088 · Signkorea · Skcommax Activex Control
Publicado
2007-03-28
·
Atualizado
2017-07-29
·
CVE-2007-1722
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SignKorea SKCommAX ActiveX control module versions 6.6.0.1 and 7.2.0.2
Description:
The issue is related to a buffer overflow in the DownloadCertificateExt function. This allows remote attackers to execute arbitrary code via a long
pszUserID argument.Recommendations:
For version 6.6.0.1, consider disabling the DownloadCertificateExt function until a patch is available.
For version 7.2.0.2, restrict the use of the
pszUserID argument in the DownloadCertificateExt function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Skcommax Activex Control