vendor:
Digital Surveillance
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Digital Surveillance
Affected Version From: 2.1.0.2
Affected Version To: 2.1.0.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 with Internet Explorer 7
RTS Sentry Digital Surveillance PTZCamPanel Class (CamPanel.dll 2.1.0.2) remote buffer overflow exploit (ie7/xp sp2)
This exploit targets the PTZCamPanelCtrl object class in the CamPanel.dll version 2.1.0.2 of RTS Sentry Digital Surveillance. It allows for remote buffer overflow, specifically on Internet Explorer 7 running on Windows XP SP2. The exploit can be accessed through the following camera demo: http://www.rtssentry.com/index.asp?PageAction=Custom&ID=10.
Mitigation:
To mitigate this vulnerability, it is recommended to update the CamPanel.dll to a patched version or to disable the PTZCamPanelCtrl object class.