vendor:
Softek Barcode Reader Toolkit ActiveX
by:
N/A
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Softek Barcode Reader Toolkit ActiveX
Affected Version From: 7.1.4.14
Affected Version To: 7.1.4.14
Patch Exists: YES
Related CWE: N/A
CPE: a:softek_software_ltd:softek_barcode_reader_toolkit_activex:7.1.4.14
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
Softek Barcode Reader Toolkit ActiveX 7.1.4.14 (SoftekATL.dll) Buffer Overflow PoC
The vulnerability is caused due to a boundary error in SoftekATL.DLL when handling the value assigned to the 'DebugTraceFile' property and can be exploited to cause a heap-based buffer overflow via an overly long string which may lead to execution of arbitrary code.
Mitigation:
Update to the latest version of Softek Barcode Reader Toolkit ActiveX.