First published: Mon Jul 06 2015(Updated: )
Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Panasonic Security Api Activex Sdk | <=8.10.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4647 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2015-4647, upgrade to the latest version of the Panasonic Security API ActiveX SDK, specifically version 8.10.18 or later.
CVE-2015-4647 can allow remote attackers to execute arbitrary code through specially crafted input.
CVE-2015-4647 affects all versions of Panasonic Security API ActiveX SDK up to and including 8.10.14.
The vulnerable properties in CVE-2015-4647 include the FilePassword property and the GetStringInfo method.