Imendio Planner Filename Remote Format String Vulnerability
BID:19307
CVE-2006-4070 |Info
Imendio Planner Filename Remote Format String Vulnerability
| Bugtraq ID: | 19307 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4070 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2006 12:00AM |
| Updated: | Jul 06 2016 01:33PM |
| Credit: | LoneEagle is credited with discovery of this vulnerability. |
| Vulnerable: |
Imendio Imendio Planner 0.13 |
| Not Vulnerable: | |
Discussion
Imendio Planner Filename Remote Format String Vulnerability
Imendio Planner is prone to a remote format-string vulnerability.
This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then entice unsuspecting users to open the malicious file with the affected application.
A successful attack may crash the application or lead to arbitrary code execution.
Version 0.13 is vulnerable to this issue; other versions may also be affected.
Imendio Planner is prone to a remote format-string vulnerability.
This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then entice unsuspecting users to open the malicious file with the affected application.
A successful attack may crash the application or lead to arbitrary code execution.
Version 0.13 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Imendio Planner Filename Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Imendio Planner Filename Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Imendio Planner Filename Remote Format String Vulnerability
References:
References: