PT-2007-3088 · Signkorea · Skcommax Activex Control

Published

2007-03-28

·

Updated

2017-07-29

·

CVE-2007-1722

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SignKorea SKCommAX ActiveX control module versions 6.6.0.1 and 7.2.0.2
Description: The issue is related to a buffer overflow in the DownloadCertificateExt function. This allows remote attackers to execute arbitrary code via a long pszUserID argument.
Recommendations: For version 6.6.0.1, consider disabling the DownloadCertificateExt function until a patch is available. For version 7.2.0.2, restrict the use of the pszUserID argument in the DownloadCertificateExt function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1722

Affected Products

Skcommax Activex Control