CVE-2007-5661
Summary
| CVE | CVE-2007-5661 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-04-04 00:44:00 UTC |
| Updated | 2017-07-29 01:33:00 UTC |
| Description | The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Macrovision | Installshield | All | sp1 | All | All |
| Application | Macrovision | Installshield | All | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20080331 Macrovision InstallShield InstallScript One-Click Install Untrusted Library Loading Vulnerability | IDEFENSE | labs.idefense.com | |
| Macrovision InstallShield InstallScript OCI Untrusted Library Remote Code Execution Vulnerability | BID | www.securityfocus.com | Patch |
| View Document | CONFIRM | knowledge.macrovision.com | Patch |
| Macrovision InstallShield InstallScript One-Click Install ActiveX Control Code Execution - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - InstallShield ActiveX Control Lets Remote Users Load and Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.