This application requires Javascript for optimal performance.

Flexera.InstallShield.ISGrid2.DLL.DoFindReplace.Buffer.Overflow

Release Date

Nov 25, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in Flexera Software InstallShield.

The vulnerability is due to insufficient validation to the arguments of the DoFindReplace() method. As a result, a remote attacker may be able to execute arbitrary code within the context of the application.

Affected Products

Flexera AdminStudio All versions
Flexera InstallShield 2011
Novell ZENworks Configuration Management 10.x
Novell ZENworks Configuration Management 11.x
Novell ZENWorks AdminStudio All versions

Recommended Actions

Currently we are not aware of any vendor supplied patches.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3174

Reference: VID-30308