CVE-2008-2437: Buffer Overflow
Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2437?
CVE-2008-2437 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-2437?
To resolve CVE-2008-2437, upgrade to the latest version of Trend Micro OfficeScan or Client Server Messaging Security that is not affected.
What systems are affected by CVE-2008-2437?
CVE-2008-2437 affects Trend Micro OfficeScan versions 7.3 (patch 4 and others), 8.0 (and SP1) and Client Server Messaging Security versions 2.0, 3.5, and 3.6.
What is the nature of the vulnerability in CVE-2008-2437?
CVE-2008-2437 is a stack-based buffer overflow vulnerability caused by improper handling of the ComputerName parameter in HTTP requests.
Can CVE-2008-2437 be exploited remotely?
Yes, CVE-2008-2437 can be exploited remotely by attackers sending crafted HTTP requests to the affected software.