CVE-2007-5605: Buffer Overflow
Published Jun 4, 2008
·Updated
Buffer overflow in the GetFileTime function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5606, and CVE-2007-5607.
Affected Software
1 affected component
HP Instant Support<=1.0.0.23
Event History
Jun 4, 2008
CVE Published
08:32 PM
Jun 5, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5605?
CVE-2007-5605 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2007-5605?
To fix CVE-2007-5605, upgrade HP Instant Support to version 1.0.0.24 or later.
3
What software is affected by CVE-2007-5605?
CVE-2007-5605 affects HP Instant Support versions prior to 1.0.0.24.
4
What type of vulnerability is CVE-2007-5605?
CVE-2007-5605 is a buffer overflow vulnerability in the GetFileTime function.
5
Can CVE-2007-5605 be exploited remotely?
Yes, CVE-2007-5605 can be exploited remotely by attackers sending a specially crafted argument.