20070522 KSign KSignSWAT ActiveX Control Multiple Buffer Overflows Vulnerabilitymailing list
http://marc.info/?l=full-disclosure&m=117981953312669&w=2 CVE-2007-2820
KSign KSignSWAT 2.0.3.3 - ActiveX Control Remote Buffer Overflow
Record summary
CVE-2007-2820 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary code via long arguments to the (1) SWAT_Init, (2) SWAT_InitEx, (3) SWAT_InitEx2, (4) SWAT_InitEx3, and (5) SWAT_Login functions.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKSign KSignSWAT 2.0.3.3 - ActiveX Control Remote Buffer OverflowExploitDB exploitby KIM Kee-hongNot analyzed1 file
References
736517vdb entry
http://osvdb.org/36517 25357Third-party advisory
http://secunia.com/advisories/25357 24088vdb entry
http://www.securityfocus.com/bid/24088 ADV-2007-1901vdb entry
http://www.vupen.com/english/advisories/2007/1901 ksign-axksignswat-bo(34417)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34417 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2820