An IBM SPSS Statistics ActiveX Control is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long argument to the Initialize function, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the victim's browser to crash.
CVE(s): CVE-2015-8530
Affected product(s) and affected version(s):
IBM SPSS Statistics 20
IBM SPSS Statistics 21
IBM SPSS Statistics 22
IBM SPSS Statistics 23
IBM SPSS Statistics 24
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/21E2rH1
X-Force Database: http://ift.tt/1NlICSm
from IBM Product Security Incident Response Team http://ift.tt/21E2rH6
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.