PT-2007-4445 · Microsoft+1 · Internet Explorer+2
Dr.Pantagon
·
Published
2007-06-11
·
Updated
2017-10-11
·
CVE-2007-3162
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Internet Download Accelerator version 5.2
idaiehlp.dll version 1.9.1.74
Description:
The issue is related to a buffer overflow in the NotSafe function within the idaiehlp ActiveX control. This can be exploited by remote attackers to cause a denial of service, specifically leading to an Internet Explorer crash, by providing a long argument.
Recommendations:
For Internet Download Accelerator version 5.2, consider disabling the idaiehlp ActiveX control until a patch is available.
Restrict access to the NotSafe function in the idaiehlp.dll to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Download Accelerator
Internet Explorer
Idaiehlp.Dll