Heap-based Buffer Overflow in SAP Crystal Reports ActiveX Control
CVE-2010-2590
Currently unrated
What is CVE-2010-2590?
The SAP Crystal Reports 2008 SP3 Fix Pack 3.2 contains a vulnerability in the CrystalPrintControl ActiveX control, specifically in PrintControl.dll version 12.3.2.753. This flaw allows remote attackers to exploit a heap-based buffer overflow by supplying an overly long value to the ServerResourceVersion property. Successful exploitation could lead to arbitrary code execution on the affected system, compromising confidentiality and integrity.