First published: Fri Mar 02 2012(Updated: )
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Personal Communications | =5.9.7.0 | |
IBM Personal Communications | =5.9.7.1 | |
IBM Personal Communications | =6.0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0201 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2012-0201, update IBM Personal Communications to version 5.9.8 or later, or 6.0.4 or later.
CVE-2012-0201 affects IBM Personal Communications versions 5.9.7.0, 5.9.7.1, and 6.0.3.0.
CVE-2012-0201 allows attackers to exploit a stack-based buffer overflow in order to execute arbitrary code remotely.
CVE-2012-0201 occurs in the pcspref.dll component of pcsws.exe in IBM Personal Communications.