PT-2007-7432 · Skyfex · Skyfex Client
Shinnai
·
Published
2007-12-31
·
Updated
2017-09-29
·
CVE-2007-6605
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SkyFex Client version 1.0
Description
The issue is related to a buffer overflow in a certain ActiveX control in SkyFexClient.ocx. This can be exploited by remote attackers to execute arbitrary code via long strings in the first four arguments to the
Start method.Recommendations
For SkyFex Client version 1.0, consider disabling the
Start method in the affected ActiveX control until a patch is available. Restrict access to the vulnerable ActiveX control to minimize the risk of exploitation. Avoid using long strings in the first four arguments to the Start method until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skyfex Client