Ultra.Office.Vulnerable.Method.ActiveX

NameUltra.Office.Vulnerable.Method.ActiveX.Control.Access
Last Updated DateOct 30, 2008
Release DateSep 23, 2008
SeverityHigh
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in Ultra Shareware Ultra Office Control.

This vulnerability is caused by a boundary error in the Ultra.OfficeControl ActiveX control when handling parameters received by the "HttpUpload()" or "Save()" method. Remote attackers may exploit this to execute arbitrary code.
Affected ProductsUltra Shareware Ultra Office Control 2.0.2008.501
Recommended ActionsUpdate to the latest version:
http://www.ultrashareware.com/Ultra-Office-Control.htm.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3878
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3879
Reference/shttp://www.securityfocus.com/bid/30861 (BugTraq)
http://www.securityfocus.com/bid/30863 (BugTraq)
Reference: VID-15866