Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-4827
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4827

Description:
Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/47770
  http://xforce.iss.net/xforce/xfdb/47771
  http://xforce.iss.net/xforce/xfdb/47769

ST
  1021529

SREASON
  http://securityreason.com/securityalert/4879

SAID
  Secunia Advisory: SA32672
  Secunia Advisory: SA32648
  Secunia Advisory: SA32609

MISC
  http://secunia.com/secunia_research/2008-54/
  http://secunia.com/secunia_research/2008-53/
  http://secunia.com/secunia_research/2008-52/

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/499830/100/0/threaded

BID
  33148


Return to the previous page.