PT-2006-1173 · Esri · Esri Arcpad

Published

2006-01-05

·

Updated

2011-03-08

·

CVE-2006-0089

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: ESRI ArcPad version 7.0.0.156
Description: The issue is related to a buffer overflow that can be triggered by a .amp file containing a COORDSYS tag with a long string attribute. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.
Recommendations: For ESRI ArcPad version 7.0.0.156, consider avoiding the use of .amp files with long string attributes in the COORDSYS tag until a fix is available. As a temporary workaround, restrict the handling of .amp files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0089

Affected Products

Esri Arcpad