PT-2009-5856 · Emc · Emc Captiva Pixtools Distributed Imaging

Published

2009-10-06

·

Updated

2024-02-14

·

CVE-2009-3573

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC Captiva PixTools Distributed Imaging version 2.2
Description The issue concerns insecure methods in the PDIControl.PDI.1 ActiveX control, allowing remote attackers to create or overwrite arbitrary files. This is achieved via the SetLogFileName and WriteToLog methods.
Recommendations For EMC Captiva PixTools Distributed Imaging version 2.2, consider disabling the SetLogFileName and WriteToLog methods as a temporary workaround until a patch is available. Restrict access to the PDIControl.PDI.1 ActiveX control to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2009-3573

Affected Products

Emc Captiva Pixtools Distributed Imaging