PT-2004-2667 · Haht · Hahtsite Scenario Server
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1763
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HAHTsite Scenario Server version 5.1 Patch 06 (build 91)
Description
The issue is related to a buffer overflow in hsrun.exe, which can be triggered by a long project name. This can cause a denial of service (crash) and potentially allow the execution of arbitrary code.
Recommendations
For HAHTsite Scenario Server version 5.1 Patch 06 (build 91), consider restricting the length of project names to prevent the buffer overflow until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hahtsite Scenario Server