Описание
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.
Ссылки
- Broken Link
- Broken Link
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken Link
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:esri:arcsde:8.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:8.3:sp1:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.0:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.0:sp1:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.0:sp2:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.1:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.1:sp1:*:*:*:*:*:*
cpe:2.3:a:esri:arcsde:9.1:sp2:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.26595
Средний
10 Critical
CVSS2
Дефекты
CWE-120
Связанные уязвимости
github
почти 4 года назад
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.
EPSS
Процентиль: 96%
0.26595
Средний
10 Critical
CVSS2
Дефекты
CWE-120