PT-2008-4874 · Anzio · Anzio Web Print Object

Francisco Falcon

·

Publicado

2008-08-29

·

Atualizado

2018-10-11

·

CVE-2008-3480

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Anzio Web Print Object (WePO) versions 3.2.19 through 3.2.24
Description The issue is a stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control, which allows remote attackers to execute arbitrary code via a long mainurl parameter.
Recommendations For versions 3.2.19 through 3.2.24, avoid using the mainurl parameter in the affected ActiveX control until a patch is available. As a temporary workaround, consider restricting access to the Anzio Web Print Object (WePO) ActiveX control to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3480

Produtos afetados

Anzio Web Print Object