CVE-2007-5606: Buffer Overflow
Published Jun 4, 2008
·Updated
Buffer overflow in the MoveFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5607.
Affected Software
1 affected component
HP Instant Support<=1.0.0.23
Remediation
Patch Available
Event History
Jun 4, 2008
CVE Published
08:32 PM
Jun 5, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5606?
CVE-2007-5606 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2007-5606?
To mitigate CVE-2007-5606, users should update HP Instant Support to version 1.0.0.24 or later.
3
What software is affected by CVE-2007-5606?
CVE-2007-5606 affects versions of HP Instant Support up to and including 1.0.0.23.
4
What type of vulnerability is CVE-2007-5606?
CVE-2007-5606 is classified as a buffer overflow vulnerability.
5
Can CVE-2007-5606 be exploited remotely?
Yes, CVE-2007-5606 can be exploited remotely by attackers leveraging long arguments.