CVE-2006-3925: Buffer Overflow
Published Jul 28, 2006
·Updated
Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Affected Software
1 affected component
Interactual Technologies Interactual Player<=2.60.12.0201
Remediation
Patch Available
Event History
Jul 28, 2006
CVE Published
11:04 PM
Jul 29, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3925?
CVE-2006-3925 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-3925?
To mitigate CVE-2006-3925, you should update to a version of InterActual Player newer than 2.6.
3
What software is affected by CVE-2006-3925?
CVE-2006-3925 affects InterActual Player versions prior to 2.6.12.0201.
4
Can CVE-2006-3925 be exploited remotely?
Yes, CVE-2006-3925 can be exploited remotely by sending a specially crafted argument to the Files method.
5
What kind of vulnerability is CVE-2006-3925?
CVE-2006-3925 is a stack-based buffer overflow vulnerability.