Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2006-5559
StatusCandidate
DescriptionThe Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
SeverityHigh
CVSS score9,3
CVSS vector(AV:N/AC:M/Au:N/C:C/I:C/A:C)
PhaseAssigned (11.07.2011)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5559
ReferencesBID : 20704
 CERT-VN : VU#589272
 FRSIRT : ADV-2007-0578
 MILW0RM : 2629
 MISC : http://blogs.technet.com/msrc/archive/2006/10/27/a...
 MISC : http://research.eeye.com/html/alerts/zeroday/20061...
 MS : MS07-009
 OSVDB : 31882
 SECTRACK : 1017127
 SECUNIA : 22452
 XF : ie-adodbconnection-Code-Execution(29837)
SecurityVulns:Microsoft Data Access Components code execution

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru