PT-2007-3813 · Livedata · Livedata Protocol Server
Published
2007-05-03
·
Updated
2017-07-29
·
CVE-2007-2489
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LiveData Protocol Server versions 5.00.045 through 5.00.061
Description
A heap-based buffer overflow issue allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file. This is achieved by causing a negative length to be used in a strncpy call.
Recommendations
For versions 5.00.045 through 5.00.061, update to version 5.00.062 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Livedata Protocol Server