CVE-2008-1647 Information

Description

The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0 2.3.0.0 and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.

Reference

http://secunia.com/advisories/29581 http://www.securityfocus.com/bid/28546 http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1207033569.ff.php http://www.vupen.com/english/advisories/2008/1050/references https://exchange.xforce.ibmcloud.com/vulnerabilities/45988 https://www.exploit-db.com/exploits/5338

Share on: