CVE-2010-2590
Description
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Crystal Reports CrystalPrintControl - ActiveX ServerResourceVersion Property Overflow (Metasploit)
Crystal Reports Viewer 12.0.0.549 - 'PrintControl.dll' ActiveX
Metasploit modules
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sap | crystal_reports | 2008 | |
References
- http://pocoftheday.blogspot.com/2010/12/crystal-reports-viewer-1200549-activex.html
- http://secunia.com/advisories/42305
- http://secunia.com/secunia_research/2010-135/
- http://www.exploit-db.com/exploits/15733
- http://www.osvdb.org/69917
- http://www.securityfocus.com/archive/1/515369/100/0/threaded
- http://www.securityfocus.com/bid/45387
- http://www.securitytracker.com/id?1024915
- https://service.sap.com/sap/support/notes/1539269
- http://pocoftheday.blogspot.com/2010/12/crystal-reports-viewer-1200549-activex.html
- http://secunia.com/advisories/42305
- http://secunia.com/secunia_research/2010-135/
- http://www.exploit-db.com/exploits/15733
- http://www.osvdb.org/69917
- http://www.securityfocus.com/archive/1/515369/100/0/threaded
- http://www.securityfocus.com/bid/45387
- http://www.securitytracker.com/id?1024915
- https://service.sap.com/sap/support/notes/1539269
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.