CVE-2007-5607: Code Injection
Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5607?
CVE-2007-5607 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2007-5607?
To mitigate CVE-2007-5607, update HP Instant Support to version 1.0.0.24 or later.
What software is affected by CVE-2007-5607?
CVE-2007-5607 affects HP Instant Support versions up to and including 1.0.0.23.
What kind of attack does CVE-2007-5607 enable?
CVE-2007-5607 allows remote attackers to execute arbitrary code on the affected system.
Is CVE-2007-5607 specific to certain versions of HP Instant Support?
Yes, CVE-2007-5607 specifically affects HP Instant Support versions 1.0.0.22 and earlier.