PT-2007-3088 · Signkorea · Skcommax Activex Control

Publicado

2007-03-28

·

Atualizado

2017-07-29

·

CVE-2007-1722

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SignKorea SKCommAX ActiveX control module versions 6.6.0.1 and 7.2.0.2
Description: The issue is related to a buffer overflow in the DownloadCertificateExt function. This allows remote attackers to execute arbitrary code via a long pszUserID argument.
Recommendations: For version 6.6.0.1, consider disabling the DownloadCertificateExt function until a patch is available. For version 7.2.0.2, restrict the use of the pszUserID argument in the DownloadCertificateExt function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1722

Produtos afetados

Skcommax Activex Control