RULE(RULE ID:322013)

Rule General Information
Release Date: 2019-06-26
Rule Name: IBM SPSS Sample Power Vsflex8l Combolist Buffer Overflow Vulnerability (CVE-2014-0895)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://www.solarwinds.com/documentation/orion/docs/releasenotes/releasenotes.htm
http://www-01.ibm.com/support/docview.wss?uid=swg1PI09800
http://www-01.ibm.com/support/docview.wss?uid=swg21666790
https://exchange.xforce.ibmcloud.com/vulnerabilities/91314
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www-01.ibm.com/support/docview.wss?uid=swg21666790