PT-2007-7432 · Skyfex · Skyfex Client
Shinnai
·
Publicado
2007-12-31
·
Atualizado
2017-09-29
·
CVE-2007-6605
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SkyFex Client version 1.0
Description
The issue is related to a buffer overflow in a certain ActiveX control in SkyFexClient.ocx. This can be exploited by remote attackers to execute arbitrary code via long strings in the first four arguments to the
Start method.Recommendations
For SkyFex Client version 1.0, consider disabling the
Start method in the affected ActiveX control until a patch is available. Restrict access to the vulnerable ActiveX control to minimize the risk of exploitation. Avoid using long strings in the first four arguments to the Start method until the issue is resolved.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Skyfex Client