First published: Wed Feb 06 2008(Updated: )
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sejoong Namo Namoinstall.1 Activex Control | =3.0.0.1 | |
Sejoong Namo ActiveSquare | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0634 is considered critical due to the potential for remote code execution.
To fix CVE-2008-0634, you should update the NamoInstaller ActiveX control to a version that does not contain this vulnerability.
CVE-2008-0634 affects NamoInstaller.dll version 3.0.0.1 and Sejoong Namo ActiveSquare version 6.
Yes, CVE-2008-0634 can be exploited remotely by attackers sending specially crafted arguments to the Install method.
If affected by CVE-2008-0634, your system could allow attackers to execute arbitrary code, which may compromise security.