PT-2007-5648 · Earth Resource Mapping+1 · Earth Resource Mapping Ncsview+1
Published
2007-09-10
·
Updated
2017-07-29
·
CVE-2007-4470
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Earth Resource Mapping NCSView versions prior to 3.4.0.242
ER Mapper ECW JPEG 2000 Plug-in versions prior to 8.1
Description
The issue is related to multiple stack-based buffer overflows in the Earth Resource Mapping NCSView ActiveX control. This allows remote attackers to execute arbitrary code via unspecified vectors.
Recommendations
For Earth Resource Mapping NCSView versions prior to 3.4.0.242, update to version 3.4.0.242 or later.
For ER Mapper ECW JPEG 2000 Plug-in versions prior to 8.1, update to version 8.1 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Er Mapper Ecw Jpeg 2000 Plug-In
Earth Resource Mapping Ncsview