PT-2007-2511 · Verisign+1 · Verisign Managed Pki Service+2
Published
2007-02-23
·
Updated
2017-07-29
·
CVE-2007-1083
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Verisign Managed PKI Service versions 2.0.0.2
Secure Messaging for Microsoft Exchange versions 2.0.0.2
Go Secure! versions 2.0.0.2
Description
The issue is related to a buffer overflow in the Configuration Checker (ConfigChk) ActiveX control. This control is located in the VSCnfChk.dll file, version 2.0.0.2. The buffer overflow can be triggered by providing long arguments to the
VerCompare method, allowing remote attackers to execute arbitrary code.Recommendations
For Verisign Managed PKI Service version 2.0.0.2, consider disabling the
VerCompare method in the ConfigChk ActiveX control until a patch is available.
For Secure Messaging for Microsoft Exchange version 2.0.0.2, restrict access to the VSCnfChk.dll file to minimize the risk of exploitation.
For Go Secure! version 2.0.0.2, avoid using the ConfigChk ActiveX control until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server
Secure Messaging For Microsoft Exchange
Verisign Managed Pki Service