First published: Tue Jan 22 2008(Updated: )
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports XI | =r2 | |
ActiveX | =enterprise_tree_control |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0379 has a high severity level due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2008-0379, update the affected software to a patched version provided by the vendor.
CVE-2008-0379 affects SAP Crystal Reports XI Release 2 and Microsoft ActiveX Enterprise Tree Control.
CVE-2008-0379 facilitates remote attacks that can lead to crashes and potential execution of arbitrary code.
The impact of CVE-2008-0379 on users includes possible service disruptions and security risks from executing malicious code.