CVE-2008-4771: Buffer Overflow

Published Oct 28, 2008
·
Updated

Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.

Affected Software

4 affected components
4xem VatCtrl Class=1.0.0.27
4xem VatCtrl Class=1.0.0.51
D-Link MPEG4 SHM Audio Control=1.7.0.5
Vivotek RTSP MPEG4 SP Control=2.0.0.39

Event History

Oct 28, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-4771?

The severity of CVE-2008-4771 is typically high due to its potential for stack-based buffer overflow exploitation.

2

How do I fix CVE-2008-4771?

To fix CVE-2008-4771, you should update the affected ActiveX controls to their latest versions as released by the respective vendors.

3

Which software is affected by CVE-2008-4771?

CVE-2008-4771 affects the 4xem VatCtrl Class versions 1.0.0.27 and 1.0.0.51, D-Link MPEG4 SHM Audio Control version 1.7.0.5, and Vivotek RTSP MPEG4 SP Control version 2.0.0.39.

4

What is the impact of CVE-2008-4771?

The impact of CVE-2008-4771 can lead to a full system compromise if an attacker successfully exploits the buffer overflow vulnerability.

5

Is CVE-2008-4771 still a concern today?

While CVE-2008-4771 was identified in 2008, systems still using the affected software versions remain vulnerable and should be addressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203