PT-2008-5961 · Db Software Laboratory · Vimp X
Shinnai
·
Published
2008-10-27
·
Updated
2017-09-29
·
CVE-2008-4750
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DB Software Laboratory VImp X version 4.8.8.0
DB Software Laboratory VImp X version 4.7.7
Description
The issue is related to a stack-based buffer overflow in the VImpX.VImpAX ActiveX control. This control is part of the DB Software Laboratory VImp X software. The overflow can be triggered via a long LogFile property, potentially allowing remote attackers to execute arbitrary code.
Recommendations
For version 4.8.8.0, consider restricting access to the VImpX.VImpAX ActiveX control until a patch is available.
For version 4.7.7, avoid using the LogFile property with long values in the affected ActiveX control until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vimp X