First published: Tue Apr 30 2013(Updated: )
Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property value.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS SamplePower | =3.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5945 is categorized as a critical severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2012-5945, upgrade to IBM SPSS SamplePower 3.0 FP1 or later.
CVE-2012-5945 affects IBM SPSS SamplePower version 3.0.0.0 prior to FP1.
CVE-2012-5945 is a buffer overflow vulnerability that can be exploited by attackers.
Yes, CVE-2012-5945 can be exploited remotely through specially crafted property values.