BUGTRAQ ID: 26818
CNCAN ID:CNCAN-2007121208
Trend Micro Antivirus plus AntiSpyware是一款反恶意软件应用程序。
Trend Micro Antivirus plus AntiSpyware处理.uue文件存在格式串错误,远程攻击者可以利用漏洞对应用程序进行拒绝服务攻击。
当解析.uue文件时Trend Micro Antivirus plus AntiSpyware等多个产品不正确检查部分字段值,导致远程内存破坏,当.uue文件的部分字段包含格式串字符时,可导致"Trend Micro Central Control Component"服务崩溃。
Trend Micro Internet Security Pro 2008
Trend Micro Internet Security 2008
Trend Micro AntiVirus plus AntiSpyware 2008
厂商解决方案
可参考如下补丁:
Trend Micro Internet Security 2008
Trend Micro tis_160_win_en_patch_pccscan1451.exe
javascript:openRelatedLink('http://solutionfile.trendmicro.com/solutio nfile/1036464/EN/tis_160_win_en_patch_pccscan1451.exe')
Trend Micro Internet Security Pro 2008
Trend Micro tis_160_win_en_patch_pccscan1451.exe
javascript:openRelatedLink('http://solutionfile.trendmicro.com/solutio nfile/1036464/EN/tis_160_win_en_patch_pccscan1451.exe')
Trend Micro AntiVirus plus AntiSpyware 2008
Trend Micro tis_160_win_en_patch_pccscan1451.exe
javascript:openRelatedLink('http://solutionfile.trendmicro.com/solutio nfile/1036464/EN/tis_160_win_en_patch_pccscan1451.exe')
暂无评论