CVE-2008-1307: Buffer Overflow
Published Mar 12, 2008
·Updated
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method.
Affected Software
1 affected component
Kingsoft Antivirus Online Update Module=2007.12.29.29
Event History
Mar 12, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1307?
CVE-2008-1307 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2008-1307?
To fix CVE-2008-1307, users should update the KingSoft Antivirus Online Update Module to a patched version.
3
What software is affected by CVE-2008-1307?
CVE-2008-1307 affects KingSoft Antivirus Online Update Module version 2007.12.29.29.
4
What type of vulnerability is CVE-2008-1307?
CVE-2008-1307 is a heap-based buffer overflow vulnerability.
5
Can CVE-2008-1307 be exploited remotely?
Yes, CVE-2008-1307 can be exploited remotely through crafted input to the affected ActiveX control.