First published: Tue Nov 20 2007(Updated: )
Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ComponentOne FlexGrid | =7.1_light |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6028 is considered critical due to the potential for remote code execution and denial of service.
To mitigate CVE-2007-6028, upgrade to a version of ComponentOne FlexGrid that is not vulnerable, or apply any available patches.
CVE-2007-6028 can be exploited via crafted long strings in certain properties, leading to stack-based buffer overflows.
CVE-2007-6028 specifically affects ComponentOne FlexGrid 7.1 Light.
Although CVE-2007-6028 was reported several years ago, the vulnerabilities in ActiveX controls remain relevant in discussions about legacy software security.