ignore security and it'll go away
Showing 1 - 1 of 1 RSS Feed

Files

SAP GUI TabOne ActiveX Control Caption List Buffer Overflow
Posted Jan 7, 2009
Authored by Carsten Eiram | Site secunia.com

Secunia Research has discovered a vulnerability in SAP GUI, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to a boundary error in the included TabOne ActiveX control (sizerone.ocx) when copying tab captions. This can be exploited to cause a heap-based buffer overflow by e.g. adding multiple tabs via the "AddTab()" method. Successful exploitation may allow execution of arbitrary code. SAP GUI 6.40 Patch 29 and SAP GUI 7.10 are both affected.

tags | advisory, overflow, arbitrary, activex
advisories | CVE-2008-4827
MD5 | f6d854e9387019c1663440299fd11826
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close