Trend Micro OfficeScan 'cgiRecvFile.exe' Buffer Overflow Vulnerability

Trend Micro OfficeScan is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.

Successful exploits may allow an attacker to execute arbitrary code within the context of the affected application. This may facilitate a complete compromise of vulnerable computers. Failed exploit attempts will likely result in denial-of-service conditions.

This issue affects the following:

OfficeScan 7.3 with Patch 4 build 1362
OfficeScan 7.0
OfficeScan 8.0
Client Server Messaging Security versions 3.6, 3.5, 3.0, and 2.0


 

Privacy Statement
Copyright 2010, SecurityFocus