PT-2006-1173 · Esri · Esri Arcpad
Publicado
2006-01-05
·
Atualizado
2011-03-08
·
CVE-2006-0089
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
ESRI ArcPad version 7.0.0.156
Description:
The issue is related to a buffer overflow that can be triggered by a .amp file containing a COORDSYS tag with a long string attribute. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.
Recommendations:
For ESRI ArcPad version 7.0.0.156, consider avoiding the use of .amp files with long string attributes in the COORDSYS tag until a fix is available. As a temporary workaround, restrict the handling of .amp files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Esri Arcpad