Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801753
Category:General
Title:Topaz Systems SigPlus Pro ActiveX Control Multiple Vulnerabilities
Summary:The host is installed with SigPlus Pro ActiveX Control and is prone; to multiple vulnerabilities.
Description:Summary:
The host is installed with SigPlus Pro ActiveX Control and is prone
to multiple vulnerabilities.

Vulnerability Insight:
The flaws are due to

- A boundary error when processing the 'KeyString' property which can be
exploited to cause a heap-based buffer overflow via an overly long string.

- A boundary error when processing the 'SetLocalIniFilePath()' method, and
'SetTabletPortPath()' method can be exploited to cause a heap-based buffer
overflow via an overly long string passed in the 'NewPath' and 'NewPortPath'
parameter respectively.

- An unsafe 'SetLogFilePath()' method creating a log file in a specified
location which can be exploited in combination with the 'SigMessage()'
method to create an arbitrary file with controlled content.

Vulnerability Impact:
Successful exploitation could allow attackers to create or overwrite
arbitrary local files and to execute arbitrary code.

Affected Software/OS:
Topaz Systems SigPlus Pro ActiveX Control Version 3.95

Solution:
Upgrade to the Topaz Systems SigPlus Pro ActiveX Control Version 4.29
or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: BugTraq ID: 46128
Common Vulnerability Exposure (CVE) ID: CVE-2011-0323
http://www.securityfocus.com/bid/46128
http://secunia.com/secunia_research/2011-1/
http://secunia.com/advisories/42800
XForce ISS Database: sigplus-sigmessage-file-overwrite(65117)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65117
Common Vulnerability Exposure (CVE) ID: CVE-2011-0324
http://secunia.com/secunia_research/2011-2/
XForce ISS Database: sigplus-keystring-bo(65114)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65114
XForce ISS Database: sigplus-newpath-bo(65115)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65115
XForce ISS Database: sigplus-newportpath-bo(65116)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65116
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.