Friday, May 6, 2016

IBM Security Bulletin: IBM SPSS Statistics ActiveX Control Buffer Overflow (CVE-2015-8530)

An IBM SPSS Statistics ActiveX Control is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long argument to the Initialize function, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the victim's browser to crash.



CVE(s): CVE-2015-8530


Affected product(s) and affected version(s):

IBM SPSS Statistics 20

IBM SPSS Statistics 21

IBM SPSS Statistics 22

IBM SPSS Statistics 23

IBM SPSS Statistics 24



Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/21E2rH1
X-Force Database: http://ift.tt/1NlICSm


from IBM Product Security Incident Response Team http://ift.tt/21E2rH6

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.