CVE-2008-0392: Buffer Overflow
Published Jan 23, 2008
·Updated
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.
Affected Software
1 affected component
Microsoft Visual Basic=6.0-sp6
Event History
Jan 23, 2008
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0392?
CVE-2008-0392 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2008-0392?
To fix CVE-2008-0392, apply the latest security updates provided by Microsoft for Visual Basic 6.0 SP6.
3
What types of attacks are possible with CVE-2008-0392?
CVE-2008-0392 allows user-assisted remote attackers to execute arbitrary code through specially crafted .dsr files.
4
Which version of Microsoft Visual Basic is affected by CVE-2008-0392?
CVE-2008-0392 affects Microsoft Visual Basic 6.0 SP6 Enterprise Edition.
5
Is user interaction required for exploiting CVE-2008-0392?
Yes, CVE-2008-0392 requires user interaction to execute the malicious .dsr file.