PT-2006-1173 · Esri · Esri Arcpad
Published
2006-01-05
·
Updated
2011-03-08
·
CVE-2006-0089
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
ESRI ArcPad version 7.0.0.156
Description:
The issue is related to a buffer overflow that can be triggered by a .amp file containing a COORDSYS tag with a long string attribute. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.
Recommendations:
For ESRI ArcPad version 7.0.0.156, consider avoiding the use of .amp files with long string attributes in the COORDSYS tag until a fix is available. As a temporary workaround, restrict the handling of .amp files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esri Arcpad