PT-2009-2596 · Borland · Borland Visibroker Smart Agent

Luigi Auriemma

·

Published

2009-08-31

·

Updated

2017-08-17

·

CVE-2008-7127

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Borland VisiBroker Smart Agent versions 08.00.00.C1.03 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a crafted packet with a large string length value to UDP port 14000. This triggers a memory allocation failure that is not properly handled.
Recommendations For Borland VisiBroker Smart Agent versions 08.00.00.C1.03 and earlier, consider restricting access to UDP port 14000 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7127

Affected Products

Borland Visibroker Smart Agent