Vulnerability Bulletins

IBM Security Bulletin: IBM SPSS Statistics ActiveX Control Buffer Overflow (CVE-2015-8530)

   
Affected software IBM
 
An IBM SPSS Statistics ActiveX Control is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long argument to the Initialize function, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the victims browser to crash.CVE(s): CVE-2015-8530Affected product(s) and affected version(s):IBM SPSS Statistics 20 IBM SPSS Statistics 21 IBM SPSS Statistics 22 IBM SPSS Statistics 23 IBM

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_spss_statistics_activex_control_buffer_overflow_cve_2015_8530?lang=en_us