First published: Tue Aug 14 2012(Updated: )
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung NET-i viewer | =1.37.120316 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4333 is rated as high due to its potential for remote code execution.
To fix CVE-2012-4333, users should update to the latest version of Samsung NET-i viewer that addresses this vulnerability.
CVE-2012-4333 affects Samsung NET-i viewer version 1.37.120316 and the associated ActiveX controls.
Yes, CVE-2012-4333 can be exploited remotely by an attacker using a malicious string in the fname parameter.
Exploiting CVE-2012-4333 can lead to arbitrary code execution on the affected system.