PT-2007-7340 · Hewlett Packard · Hp Software Update+1

Porkythepig

·

Publicado

2007-12-20

·

Atualizado

2018-10-15

·

CVE-2007-6506

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Software Update versions 3.0.8.4 through 4.000.005.007
Description The issue allows remote attackers to overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly access arbitrary files via the LoadDataFromFile method.
Recommendations For HP Software Update versions 3.0.8.4 through 4.000.005.007, consider disabling the SaveToFile and LoadDataFromFile methods until a patch is available. Restrict access to the RulesEngine.dll to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-6506

Produtos afetados

Hp Software Update
Rulesengine.Dll