vendor:
Unknown
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Unknown
Affected Version From: 2.0.1
Affected Version To: 2.0.1
Patch Exists: NO
Related CWE: Unknown
CPE: eCentrex VOIP Client module (uacomx.ocx)
Platforms Tested: Windows XP SP2 with Internet Explorer 6
2007
eCentrex VOIP Client module (uacomx.ocx 2.0.1) remote buffer overflow exploit
Passing more than 164 chars to ReInit method in Username argument causes a buffer overflow in the eCentrex VOIP Client module (uacomx.ocx 2.0.1) on IE6 / XP SP2. This leads to an access violation and overwrites the structured exception handler (SEH).
Mitigation:
Unknown