CVE-2007-3454: Buffer Overflow
Published Jun 27, 2007
·Updated
Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library.
Affected Software
2 affected components
Trend Micro OfficeScan=7.3
Trend Micro OfficeScan=8.0
Remediation
Patch Available
Event History
Jun 27, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3454?
CVE-2007-3454 is considered critical due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2007-3454?
To fix CVE-2007-3454, update Trend Micro OfficeScan to version 8.0.0.1042 or later.
3
What software is affected by CVE-2007-3454?
CVE-2007-3454 affects Trend Micro OfficeScan Corporate Edition versions 7.3 and 8.0.
4
What type of attack does CVE-2007-3454 allow?
CVE-2007-3454 allows a stack-based buffer overflow attack through long crafted requests.
5
Is CVE-2007-3454 a local or remote vulnerability?
CVE-2007-3454 is a remote vulnerability, exploitable by attackers over the network.