PT-2007-3237 · Akamai Technologies · Akamai Download Manager Activex Control

Publicado

2007-04-18

·

Atualizado

2018-10-16

·

CVE-2007-1891

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Akamai Technologies Download Manager ActiveX Control versions 2.0.4.4 through 2.2.1.0
Description: The issue is related to a stack-based buffer overflow in the GetPrivateProfileSectionW function, which can be exploited by remote attackers to execute arbitrary code. This is due to the misinterpretation of the nSize parameter as a byte count instead of a wide character count.
Recommendations: For versions 2.0.4.4 through 2.2.1.0, update to version 2.2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetPrivateProfileSectionW function until a patch is available. Avoid using the nSize parameter in the affected function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1891

Produtos afetados

Akamai Download Manager Activex Control