PT-2011-2271 · Topaz Systems · Sigplus Pro Activex Control
Publicado
2011-02-07
·
Atualizado
2017-08-17
·
CVE-2011-0324
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Topaz Systems SigPlus Pro ActiveX Control versions 3.95 through 4.28
Description
The issue is related to multiple heap-based buffer overflows that can be triggered by remote attackers. This can be achieved via a long
KeyString property, NewPath parameter to the SetLocalIniFilePath method, or NewPortPath parameter to the SetTabletPortPath method.Recommendations
For Topaz Systems SigPlus Pro ActiveX Control versions 3.95 through 4.28, update to version 4.29 or later to resolve the issue.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sigplus Pro Activex Control