vendor:
Barcode ActiveX
by:
callAX, GoodFellas Security Research Team
7.5
CVSS
HIGH
Stack Buffer Overflow
Buffer Overflow
CWE
Product Name: Barcode ActiveX
Affected Version From: 4.9
Affected Version To: 4.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2, Windows XP SP2 with IE 6.0 / 7.0, Windows Vista Professional SP1 with IE 7.0
2007
BarCodeAx.dll v. 4.9 ActiveX Control Remote Stack Buffer Overflow
The BeginPrint method in BarCodeAx.dll is vulnerable to a stack buffer overflow. An attacker can exploit this vulnerability remotely.
Mitigation:
Activate the Kill bit zero in CLSID:C26D9CA8-6747-11D5-AD4B-C01857C10000 or unregister BarCodeAx.dll using regsvr32