CVE-2007-1083
Summary
| CVE | CVE-2007-1083 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-23 02:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VeriSign Configuration Checker ActiveX Control Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VeriSign ConfigChk ActiveX Control Buffer Overflow - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VeriSign Managed PKI Stack Overflow in ConfigChk ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| labs.idefense.com/intelligence/vulnerabilities/display.php | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | |
| osvdb.org/33479 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| VeriSign Go Secure! Stack Overflow in ConfigChk ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [VIM] Verisign ConfigChk ActiveX Overflow(s) | af854a3a-2127-422b-91ae-364da2661108 | attrition.org | |
| VeriSign Secure Messaging for Microsoft Exchange Stack Overflow in ConfigChk ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| RETIRED: VeriSign ConfigCHK ActiveX Control VerCompare Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| JVNVU#308087: ベリサインの ActiveX コントロールにおけるバッファオーバーフローの脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| download.verisign.co.jp/support/announce/20070216.html | af854a3a-2127-422b-91ae-364da2661108 | download.verisign.co.jp | Vendor Advisory |
| VU#308087 - VeriSign Managed PKI Configuration Checker ActiveX control stack buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [VIM] Verisign ConfigChk ActiveX Overflow(s) | af854a3a-2127-422b-91ae-364da2661108 | attrition.org | |
| www.jpcert.or.jp/at/2007/at070006.txt | af854a3a-2127-422b-91ae-364da2661108 | www.jpcert.or.jp | |
| MISC:http://jvn.jp/cert/JVNVU%23308087/index.html | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.