PT-2006-2194 · Cryptomathic · Cryptomathic Cenroll Activex Control
Published
2006-05-09
·
Updated
2018-10-18
·
CVE-2006-1172
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cryptomathic Cenroll ActiveX Control version 1.1.0.0
Description
The issue is related to a stack-based buffer overflow in the createPKCS10 function, which can be exploited by remote attackers to execute arbitrary code. This is achieved through vectors related to the TDC Digital signature.
Recommendations
For Cryptomathic Cenroll ActiveX Control version 1.1.0.0, consider disabling the createPKCS10 function as a temporary workaround until a patch is available. Restrict access to the ActiveX Control to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cryptomathic Cenroll Activex Control