PT-2008-5981 · 4Xem+2 · 4Xem Vatctrl Class+2
Rgod
·
Published
2008-10-28
·
Updated
2017-09-29
·
CVE-2008-4771
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
4xem VatCtrl Class versions 1.0.0.27 through 1.0.0.51
D-Link MPEG4 SHM Audio Control version 1.7.0.5
Vivotek RTSP MPEG4 SP Control version 2.0.0.39
Description
The issue is a stack-based buffer overflow in the VATDecoder.VatCtrl.1 ActiveX control. This allows remote attackers to execute arbitrary code via a long
Url property.Recommendations
For 4xem VatCtrl Class versions 1.0.0.27 through 1.0.0.51, consider disabling the
Url property in the ActiveX control until a patch is available.
For D-Link MPEG4 SHM Audio Control version 1.7.0.5, restrict access to the vulnerable ActiveX control to minimize the risk of exploitation.
For Vivotek RTSP MPEG4 SP Control version 2.0.0.39, avoid using the Url property in the affected control until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
4Xem Vatctrl Class
D-Link Mpeg4 Shm Audio Control
Vivotek Rtsp Mpeg4 Sp Control