Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL...
Vulnerability Description
Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2570
Credits & Attribution
No credits recorded in the NVD database.
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-008
- http://www.securityfocus.com/bid/34766
- http://www.vupen.com/english/advisories/2009/1221
- http://secunia.com/advisories/34925
- http://retrogod.altervista.org/9sg_symantec_win_fuck_pro.html
- http://www.securitytracker.com/id?1022147
- http://www.securityfocus.com/archive/1/503086/100/0/threaded
- http://osvdb.org/54137
- http://www.securityfocus.com/archive/1/503074/100/0/threaded
- http://www.securityfocus.com/archive/1/503163/100/0/threaded
More from symantec
View All →Affected Vendor
symantec
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.