PT-2008-5431 · Componentone · Vsflexgrid

Publicado

2008-09-19

·

Atualizado

2017-08-08

·

CVE-2008-4132

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ComponentOne VSFlexGrid versions 7.0.1.151 through 8.0.20072.239
Description The issue is related to a stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control. This can be exploited by remote attackers to execute arbitrary code via a long first argument to the Archive method.
Recommendations For versions 7.0.1.151 through 8.0.20072.239, consider disabling the Archive method in the VSFlexGrid.VSFlexGridL ActiveX control as a temporary workaround until a patch is available. Restrict access to this control to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4132

Produtos afetados

Vsflexgrid