Описание
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
Ссылки
- Mailing ListThird Party Advisory
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Vendor Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Vendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:esri:arcinfo_workstation:9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00697
Низкий
7.2 High
CVSS2
Дефекты
CWE-134
Связанные уязвимости
github
почти 4 года назад
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
EPSS
Процентиль: 71%
0.00697
Низкий
7.2 High
CVSS2
Дефекты
CWE-134