vendor:
Office Viewer Component
by:
shinnai
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Office Viewer Component
Affected Version From: 5.3
Affected Version To: 5.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
EDraw Office Viewer Component 5.3 “FtpDownloadFile()” Remote BoF
The EDraw Office Viewer Component 5.3 is vulnerable to a remote Buffer Overflow in the "FtpDownloadFile()" function. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable component, leading to arbitrary code execution.
Mitigation:
The vendor has not released a patch or mitigation for this vulnerability. It is recommended to avoid using the vulnerable component or implement strong input validation to prevent buffer overflow attacks.