RULE(RULE ID:322372)

Rule General Information
Release Date: 2019-07-05
Rule Name: SAP GUI TabOne Caption Buffer Overflow Vulnerability (CVE-2008-4827)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference:
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://secunia.com/