PT-2007-4445 · Microsoft+1 · Internet Explorer+2

Dr.Pantagon

·

Published

2007-06-11

·

Updated

2017-10-11

·

CVE-2007-3162

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Internet Download Accelerator version 5.2 idaiehlp.dll version 1.9.1.74
Description: The issue is related to a buffer overflow in the NotSafe function within the idaiehlp ActiveX control. This can be exploited by remote attackers to cause a denial of service, specifically leading to an Internet Explorer crash, by providing a long argument.
Recommendations: For Internet Download Accelerator version 5.2, consider disabling the idaiehlp ActiveX control until a patch is available. Restrict access to the NotSafe function in the idaiehlp.dll to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3162

Affected Products

Internet Download Accelerator
Internet Explorer
Idaiehlp.Dll