PT-2006-6769 · Business Objects · Visual Studio Crystal Reports
Publicado
2006-11-28
·
Atualizado
2018-10-17
·
CVE-2006-6133
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Visual Studio Crystal Reports versions .NET 2002 through 2005 SP1
Description
A stack-based buffer overflow issue allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file. This issue affects various versions of Visual Studio Crystal Reports, formerly known as Business Objects Crystal Reports XI Professional.
Recommendations
For versions .NET 2002 through 2005 SP1, consider avoiding the use of crafted RPT files until a fix is available. As a temporary workaround, restrict the handling of RPT files to minimize the risk of exploitation.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Visual Studio Crystal Reports