CVE-2011-0340
Last modified
CVE-2011-0340 is a vulnerability of currently unknown severity. Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.. EPSS estimates a 32.35% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Advantech | Advantech Studio | 6.1 | Sp6 61.6.01.05 |
| Indusoft | Thin Client | 7.0 | — |
| Indusoft | Web Studio | <= 7.0 | — |
| Indusoft | Web Studio | 6.1 | — |
References
- http://secunia.com/advisories/42928Vendor Advisory
- http://secunia.com/advisories/43116Vendor Advisory
- http://secunia.com/secunia_research/2011-36/Vendor Advisory
- http://secunia.com/secunia_research/2011-37/Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1115Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1116Vendor Advisory
- http://secunia.com/advisories/42928Vendor Advisory
- http://secunia.com/advisories/43116Vendor Advisory
- http://secunia.com/secunia_research/2011-36/Vendor Advisory
- http://secunia.com/secunia_research/2011-37/Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1115Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1116Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0340?
How severe is CVE-2011-0340?
How do I fix CVE-2011-0340?
Are you affected by CVE-2011-0340?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
