First published: Tue Oct 02 2018(Updated: )
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Gigasoft Proessentials | <=5 | |
Ge Ge Communicator | <=3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7908 is considered high due to the potential for remote code execution.
To fix CVE-2017-7908, upgrade Gigasoft Proessentials to a version later than 5 and GE Communicator to a version later than 3.15.
CVE-2017-7908 affects Gigasoft Proessentials version 5 and prior, as well as GE Communicator version 3.15 and prior.
CVE-2017-7908 is classified as a heap-based buffer overflow vulnerability.
Yes, CVE-2017-7908 can be exploited remotely through a malicious HTML file that loads ActiveX controls.