PT-2018-16813 · Barcodewiz · Barcodewiz Barcode

Hyp3Rlinx

+1

·

Published

2018-01-09

·

Updated

2018-01-30

·

CVE-2018-5221

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BarCodeWiz BarCode versions prior to 6.7
Description The issue is related to multiple buffer overflows in the BarCodeWiz BarCode ActiveX control. This can be exploited by remote attackers to execute arbitrary code via a long argument to the BottomText or TopText property.
Recommendations For versions prior to 6.7, update to version 6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the BottomText and TopText properties until the update is applied.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5221

Affected Products

Barcodewiz Barcode