PT-2007-3830 · Progress · Progress+1
Publicado
2007-05-04
·
Atualizado
2018-10-16
·
CVE-2007-2506
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Progress OpenEdge versions 10.x
Progress Software Progress versions 9.1e and certain other 9.x versions
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and daemon hang. This can be achieved by invoking
edit.r with no additional parameters via a messenger URL. For example, requests for cgiip.exe or wsisa.dll with WService=wsbroker1/ edit.r in the PATH INFO can demonstrate this.Recommendations
For Progress OpenEdge versions 10.x, update to a version that includes a fix for this issue.
For Progress Software Progress versions 9.1e and certain other 9.x versions, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the
edit.r URL to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Progress
Progress Openedge