CVE-2014-3912: Buffer Overflow
Published Jun 5, 2014
·Updated
Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPOLiS Device Manager before 1.8.7 allows remote attackers to execute arbitrary code via a long value.
Affected Software
1 affected component
Samsung iPOLiS Device Manager<=1.8.2
Remediation
Patch Available
Event History
Jun 5, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3912?
CVE-2014-3912 is considered a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-3912?
To mitigate CVE-2014-3912, update Samsung iPOLiS Device Manager to version 1.8.7 or later.
3
Which versions of Samsung iPOLiS Device Manager are affected by CVE-2014-3912?
Versions of Samsung iPOLiS Device Manager before 1.8.7 are affected by CVE-2014-3912.
4
What kind of attack is possible with CVE-2014-3912?
CVE-2014-3912 allows remote attackers to execute arbitrary code on the affected system.
5
Is CVE-2014-3912 related to ActiveX controls?
Yes, CVE-2014-3912 is associated with a stack-based buffer overflow in an ActiveX control used by Samsung iPOLiS Device Manager.