CVE-2008-0379: Buffer Overflow
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0379?
CVE-2008-0379 has a high severity level due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2008-0379?
To fix CVE-2008-0379, update the affected software to a patched version provided by the vendor.
What software is affected by CVE-2008-0379?
CVE-2008-0379 affects SAP Crystal Reports XI Release 2 and Microsoft ActiveX Enterprise Tree Control.
What type of attack does CVE-2008-0379 facilitate?
CVE-2008-0379 facilitates remote attacks that can lead to crashes and potential execution of arbitrary code.
What is the impact of CVE-2008-0379 on users?
The impact of CVE-2008-0379 on users includes possible service disruptions and security risks from executing malicious code.