PT-2007-4450 · Vivotek · Vivotek Motion Jpeg Activex Control

Rgod

·

Published

2007-06-11

·

Updated

2017-10-11

·

CVE-2007-3167

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vivotek Motion Jpeg ActiveX control version 2.0.0.13
Description: The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved by providing a long value for the PtzUrl property.
Recommendations: For version 2.0.0.13, consider disabling the PtzUrl property or restricting its use to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3167

Affected Products

Vivotek Motion Jpeg Activex Control