CVE-2017-7908: Buffer Overflow
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7908?
The severity of CVE-2017-7908 is considered high due to the potential for remote code execution.
How do I fix CVE-2017-7908?
To fix CVE-2017-7908, upgrade Gigasoft Proessentials to a version later than 5 and GE Communicator to a version later than 3.15.
What platforms are affected by CVE-2017-7908?
CVE-2017-7908 affects Gigasoft Proessentials version 5 and prior, as well as GE Communicator version 3.15 and prior.
What type of vulnerability is CVE-2017-7908?
CVE-2017-7908 is classified as a heap-based buffer overflow vulnerability.
Can CVE-2017-7908 be exploited remotely?
Yes, CVE-2017-7908 can be exploited remotely through a malicious HTML file that loads ActiveX controls.