CVE-2007-1083

Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
References
Link Resource
http://attrition.org/pipermail/vim/2007-February/001384.html
http://attrition.org/pipermail/vim/2007-February/001385.html
http://jvn.jp/cert/JVNVU%23308087/index.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479
http://osvdb.org/33479
http://secunia.com/advisories/24249 Vendor Advisory
http://www.jpcert.or.jp/at/2007/at070006.txt
http://www.kb.cert.org/vuls/id/308087 US Government Resource
http://www.securityfocus.com/bid/22671
http://www.securityfocus.com/bid/22676
http://www.securitytracker.com/id?1017692
http://www.securitytracker.com/id?1017693
http://www.securitytracker.com/id?1017694
http://www.vupen.com/english/advisories/2007/0702
https://download.verisign.co.jp/support/announce/20070216.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32639
http://attrition.org/pipermail/vim/2007-February/001384.html
http://attrition.org/pipermail/vim/2007-February/001385.html
http://jvn.jp/cert/JVNVU%23308087/index.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479
http://osvdb.org/33479
http://secunia.com/advisories/24249 Vendor Advisory
http://www.jpcert.or.jp/at/2007/at070006.txt
http://www.kb.cert.org/vuls/id/308087 US Government Resource
http://www.securityfocus.com/bid/22671
http://www.securityfocus.com/bid/22676
http://www.securitytracker.com/id?1017692
http://www.securitytracker.com/id?1017693
http://www.securitytracker.com/id?1017694
http://www.vupen.com/english/advisories/2007/0702
https://download.verisign.co.jp/support/announce/20070216.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32639
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:verisign:mpki:*:*:*:*:*:*:*:*
cpe:2.3:a:verisign:mpki:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:verisign:mpki:5.0:*:*:*:*:*:*:*
cpe:2.3:a:verisign:mpki:6.0:*:*:*:*:*:*:*
cpe:2.3:a:verisign:mpki:7.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:27

Type Values Removed Values Added
References () http://attrition.org/pipermail/vim/2007-February/001384.html - () http://attrition.org/pipermail/vim/2007-February/001384.html -
References () http://attrition.org/pipermail/vim/2007-February/001385.html - () http://attrition.org/pipermail/vim/2007-February/001385.html -
References () http://jvn.jp/cert/JVNVU%23308087/index.html - () http://jvn.jp/cert/JVNVU%23308087/index.html -
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479 -
References () http://osvdb.org/33479 - () http://osvdb.org/33479 -
References () http://secunia.com/advisories/24249 - Vendor Advisory () http://secunia.com/advisories/24249 - Vendor Advisory
References () http://www.jpcert.or.jp/at/2007/at070006.txt - () http://www.jpcert.or.jp/at/2007/at070006.txt -
References () http://www.kb.cert.org/vuls/id/308087 - US Government Resource () http://www.kb.cert.org/vuls/id/308087 - US Government Resource
References () http://www.securityfocus.com/bid/22671 - () http://www.securityfocus.com/bid/22671 -
References () http://www.securityfocus.com/bid/22676 - () http://www.securityfocus.com/bid/22676 -
References () http://www.securitytracker.com/id?1017692 - () http://www.securitytracker.com/id?1017692 -
References () http://www.securitytracker.com/id?1017693 - () http://www.securitytracker.com/id?1017693 -
References () http://www.securitytracker.com/id?1017694 - () http://www.securitytracker.com/id?1017694 -
References () http://www.vupen.com/english/advisories/2007/0702 - () http://www.vupen.com/english/advisories/2007/0702 -
References () https://download.verisign.co.jp/support/announce/20070216.html - Vendor Advisory () https://download.verisign.co.jp/support/announce/20070216.html - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/32639 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/32639 -

Information

Published : 2007-02-23 02:28

Updated : 2024-11-21 00:27


NVD link : CVE-2007-1083

Mitre link : CVE-2007-1083

CVE.ORG link : CVE-2007-1083


JSON object : View

Products Affected

verisign

  • mpki
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer