vendor:
by:
shinnai
7.5
CVSS
HIGH
Denial of Service
Stack-based Buffer Overflow
CWE
Product Name:
Affected Version From: ccrpbds6.dll
Affected Version To: ccrpbds6.dll
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
BrowseDialog Class (ccrpbds6.dll) multiple methods Denial of Service
The BrowseDialog class in ccrpbds6.dll is vulnerable to a Denial of Service attack. The vulnerability is caused by two methods in the DLL that are unable to handle long strings, leading to a stack overflow. This vulnerability can be triggered by selecting the 'IsFolderAvailable' or 'RootFolder' options in the dropdown menu and clicking the 'Click here to start the test' button.
Mitigation:
To mitigate this vulnerability, it is recommended to update the affected DLL to a patched version that handles long strings correctly.