AXIS.Communications.Camera.Control

NameAXIS.Communications.Camera.Control.Buffer.Overflow
Release DateMar 05, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in the ActiveX Camera Control by AXIS Communications.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted web page. It allows a remote attacker to execute arbitrary code.
Affected ProductsAXIS Camera Control version 2.40.0.0 and previous versions
Recommended ActionsContact your vendor for upgrade or patch information:
http://www.axis.com/techsup/software/amc/index.htm.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5260
Reference/shttp://www.securityfocus.com/bid/33408 (BugTraq)
http://www.vupen.com/english/advisories/2009/0228 (FrSIRT)
Reference: VID-17304