PT-2008-5981 · 4Xem+2 · 4Xem Vatctrl Class+2
Rgod
·
Publicado
2008-10-28
·
Atualizado
2017-09-29
·
CVE-2008-4771
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
4xem VatCtrl Class versions 1.0.0.27 through 1.0.0.51
D-Link MPEG4 SHM Audio Control version 1.7.0.5
Vivotek RTSP MPEG4 SP Control version 2.0.0.39
Description
The issue is a stack-based buffer overflow in the VATDecoder.VatCtrl.1 ActiveX control. This allows remote attackers to execute arbitrary code via a long
Url property.Recommendations
For 4xem VatCtrl Class versions 1.0.0.27 through 1.0.0.51, consider disabling the
Url property in the ActiveX control until a patch is available.
For D-Link MPEG4 SHM Audio Control version 1.7.0.5, restrict access to the vulnerable ActiveX control to minimize the risk of exploitation.
For Vivotek RTSP MPEG4 SP Control version 2.0.0.39, avoid using the Url property in the affected control until the issue is resolved.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
4Xem Vatctrl Class
D-Link Mpeg4 Shm Audio Control
Vivotek Rtsp Mpeg4 Sp Control