The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: some of these details are obtained from third party information.
References
Configurations
History
21 Nov 2024, 00:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/30548 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/29579 - | |
References | () http://www.vupen.com/english/advisories/2008/1768/references - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/42896 - | |
References | () https://www.exploit-db.com/exploits/5750 - |
Information
Published : 2008-06-12 12:21
Updated : 2024-11-21 00:47
NVD link : CVE-2008-2684
Mitre link : CVE-2008-2684
CVE.ORG link : CVE-2008-2684
JSON object : View
Products Affected
blackice
- black_ice_barcode_sdk
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')