CVE-2008-2283
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.
Published:May 18, 2008
Last Modified:Apr 23, 2026
EPS:May 18, 2008
EPSS Score:0.05681
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Idautomation
Product
Aztec Barcode
Idautomation
Aztec Barcode
Vendor
Idautomation
Product
Datamatrix Barcode
Idautomation
Datamatrix Barcode
Vendor
Idautomation
Product
Linear Barcode
Idautomation
Linear Barcode
Vendor
Idautomation
Product
Pdf417 Barcode
Idautomation
Pdf417 Barcode
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
