PT-2007-1598 · Packeteer · Packeteer Packetshaper Packetwise
Kian Mohageri
·
Published
2007-01-09
·
Updated
2018-10-16
·
CVE-2007-0113
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Packeteer PacketShaper PacketWise versions 8.x
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a reset or reboot, by exploiting a buffer overflow. This can be achieved through either a long traffic class argument to the "class show" command or a long POLICY parameter value in
clastree.htm.Recommendations
For Packeteer PacketShaper PacketWise versions 8.x, consider restricting access to the
class show command and limiting the length of the POLICY parameter value in clastree.htm to prevent exploitation until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Packeteer Packetshaper Packetwise