PT-2007-6945 · Componentone · Componentone Flexgrid

Elazar Broad

·

Publicado

2007-11-20

·

Atualizado

2017-07-29

·

CVE-2007-6028

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ComponentOne FlexGrid version 7.1 Light
Description The issue is related to multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control. This can be exploited by remote attackers who send a long string in the Text, EditSelText, EditText, and CellFontName property values, potentially leading to a denial of service and possibly the execution of arbitrary code.
Recommendations For ComponentOne FlexGrid version 7.1 Light, consider disabling the VSFlexGrid.VSFlexGridL ActiveX control until a patch is available to prevent potential exploitation. Avoid using long strings in the Text, EditSelText, EditText, and CellFontName property values to minimize the risk of triggering the buffer overflows.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6028

Produtos afetados

Componentone Flexgrid