OfficeScanSetupINI.dll ’Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX’多个缓冲区溢出

漏洞信息详情

OfficeScanSetupINI.dll ’Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX’多个缓冲区溢出

漏洞简介

OfficeScanSetupINI.dll的Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX控件中存在多个缓冲区溢出。当在OfficeScan Build 1344版本之前的7.0版本, OfficeScan Build 1241版本之前的7.3版本以及Client / Server / Messaging Security Build 1197版本之前的3.0版本中运行时,远程攻击者可以借助一个特制的HTML文件,执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Trend Micro OfficeScan Corporate Edition 7.3

Trend Micro osce_73_win_en_securitypatch_b1241.exe

http://www.trendmicro.com/ftp/products/patches/osce_73_win_en_security patch_b1241.exe

Trend Micro OfficeScan Corporate Edition 7.0

Trend Micro osce_70_win_en_securitypatch_b1344.exe

http://www.trendmicro.com/ftp/products/patches/osce_70_win_en_security patch_b1344.exe

参考网址

来源: US-CERT

名称: VU#784369

链接:http://www.kb.cert.org/vuls/id/784369

来源: SECUNIA

名称: 24193

链接:http://secunia.com/advisories/24193

来源: www.trendmicro.com

链接:http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt

来源: SECTRACK

名称: 1017664

链接:http://www.securitytracker.com/id?1017664

来源: BID

名称: 22585

链接:http://www.securityfocus.com/bid/22585

来源: VUPEN

名称: ADV-2007-0638

链接:http://www.frsirt.com/english/advisories/2007/0638

来源: OSVDB

名称: 33040

链接:http://osvdb.org/33040

来源: esupport.trendmicro.com

链接:http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享