PT-2009-4805 · Avax · Avax Vector Activex

Publicado

2009-07-08

·

Atualizado

2018-10-10

·

CVE-2009-2377

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Avax Vector ActiveX version 1.3
Description The issue is related to a buffer overflow in the Avax Vector ActiveX control, specifically in the avPreview.ocx component. This can be exploited by remote attackers to cause a denial of service, resulting in an application crash. The exploitation occurs via a long PrinterName property.
Recommendations For Avax Vector ActiveX version 1.3, consider restricting the length of the PrinterName property to prevent buffer overflow exploitation until a patch is available. As a temporary workaround, avoid using excessively long printer names in the affected ActiveX control.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2377

Produtos afetados

Avax Vector Activex