First published: Sat Jul 18 2015(Updated: )
Multiple stack-based buffer overflows in the SafeShellExecute method in the NetIQExecObject.NetIQExec.1 ActiveX control in NetIQExec.dll in NetIQ Security Solutions for iSeries 8.1 allow remote attackers to execute arbitrary code via long arguments, aka ZDI-CAN-2699.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Security Solutions For Iseries | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-0795 is considered high due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2015-0795, it is recommended to apply the latest security patches provided by Micro Focus for Security Solutions for iSeries 8.1.
CVE-2015-0795 specifically affects the NetIQ Security Solutions for iSeries version 8.1.
Yes, CVE-2015-0795 can be exploited remotely by attackers sending long arguments to the vulnerable ActiveX control.
CVE-2015-0795 is classified as a stack-based buffer overflow vulnerability.