PT-2005-2390 · Esri · Esri Arcinfo Workstation

Kevin Finisterre

·

Published

2005-05-02

·

Updated

2016-10-18

·

CVE-2005-1393

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ESRI ArcInfo Workstation version 9.0
Description: The issue concerns multiple buffer overflows that allow local users to execute arbitrary code. This is achieved by providing long command line arguments to certain executables, including (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.
Recommendations: For ESRI ArcInfo Workstation version 9.0, update to a newer version that contains a fix for this issue to prevent arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1393

Affected Products

Esri Arcinfo Workstation