Barcodewiz v3.29 Barcode ActiveX Control Buffer Overflow

Strike ID:
E10-flu01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2010

Description

This strike exploits a buffer overflow vulnerability in Barcodewiz v3.29 when calling the LoadProperties function. The argument passed is not properly validated, and an overly large value can overflow the buffer causing a denial of service condition, as well as allowing for remote code to possibly be executed.

CVE

Bid