PT-2008-1951 · Borland · Starteam Multicast Service+1
Published
2008-04-06
·
Updated
2017-08-08
·
CVE-2008-0311
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Borland CaliberRM 2006 version 6.4
Description
The issue is related to a stack-based buffer overflow in the PGMWebHandler::parse request function within the StarTeam Multicast Service component. This allows remote attackers to execute arbitrary code by sending a large HTTP request.
Recommendations
For version 6.4, consider restricting access to the StarTeam Multicast Service component until a fix is available. As a temporary workaround, limiting the size of HTTP requests to the PGMWebHandler could help minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Borland Caliberrm
Starteam Multicast Service