PT-2007-4452 · Microsoft+1 · Internet Explorer+1

Shinnai

·

Publicado

2007-06-11

·

Atualizado

2017-10-11

·

CVE-2007-3169

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: EDraw Office Viewer Component versions 4.0.5.20 through 4.0, and other versions before 5.0
Description: The issue is related to a buffer overflow in a certain ActiveX control. This can be exploited by remote attackers to cause a denial of service, such as crashing Internet Explorer 7, or to execute arbitrary code. The exploitation occurs via a long first argument to the HttpDownloadFile method.
Recommendations: For versions 4.0.5.20 through 4.0, and other versions before 5.0, update to version 5.0 or later to resolve the issue.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-3169

Produtos afetados

Edraw Office Viewer
Internet Explorer