PT-2008-1951 · Borland · Starteam Multicast Service+1

Published

2008-04-06

·

Updated

2017-08-08

·

CVE-2008-0311

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Borland CaliberRM 2006 version 6.4
Description The issue is related to a stack-based buffer overflow in the PGMWebHandler::parse request function within the StarTeam Multicast Service component. This allows remote attackers to execute arbitrary code by sending a large HTTP request.
Recommendations For version 6.4, consider restricting access to the StarTeam Multicast Service component until a fix is available. As a temporary workaround, limiting the size of HTTP requests to the PGMWebHandler could help minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0311

Affected Products

Borland Caliberrm
Starteam Multicast Service