Business Objects Crystal Reports XI Professional File Handling Buffer Overflow Vulnerability
BID:21261
Info
Business Objects Crystal Reports XI Professional File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 21261 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-6133 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2006 12:00AM |
| Updated: | Sep 20 2007 09:20PM |
| Credit: | LSsec is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Visual Studio 2005 Team Edition for Testers 0 Microsoft Visual Studio 2005 Team Edition for Developers 0 Microsoft Visual Studio 2005 Team Edition for Architects 0 Microsoft Visual Studio 2005 Team Edition 0 Microsoft Visual Studio 2005 Standard Edition 0 Microsoft Visual Studio 2005 Professional Edition 0 Microsoft Visual Studio 2005 SP1 Microsoft Visual Studio 2005 Microsoft Visual Studio .NET Professional Edition Microsoft Visual Studio .NET Enterprise Developer Edition Microsoft Visual Studio .NET Enterprise Architect Edition Microsoft Visual Studio .NET Academic Edition 0 Microsoft Visual Studio .NET 2003 Enterprise Architect Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual Studio .NET 2003 Microsoft Visual Studio .NET 2002 SP1 Microsoft Visual Studio .NET 2002 Business Objects Crystal Reports XI Professional 0 Business Objects Crystal Reports for Visual Studio .NET 2005 10.2 Business Objects Crystal Reports for Visual Studio .NET 2003 0 Business Objects Crystal Reports for Visual Studio .NET 2002 0 Business Objects Crystal Enterprise 10.0 Business Objects BusinessObjects Enterprise XI 0 Business Objects Business Objects Enterprise XIr2 |
| Not Vulnerable: | |
Discussion
Business Objects Crystal Reports XI Professional File Handling Buffer Overflow Vulnerability
Business Objects Crystal Reports XI Professional is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An atacker may exploit this issue by enticing a victim user into opening a malicious document file, resulting in the execution of arbitrary code with privileges of the vulnerable application. Failed exploit attemtps will likely result in denial-of-service conditions.
Business Objects Crystal Reports XI Professional is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An atacker may exploit this issue by enticing a victim user into opening a malicious document file, resulting in the execution of arbitrary code with privileges of the vulnerable application. Failed exploit attemtps will likely result in denial-of-service conditions.
Exploit / POC
Business Objects Crystal Reports XI Professional File Handling Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Business Objects Crystal Reports XI Professional File Handling Buffer Overflow Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the referenced advisories for more information.
Business Objects Crystal Reports for Visual Studio .NET 2003 0
Business Objects Crystal Reports for Visual Studio .NET 2002 0
Microsoft Visual Studio 2005
Business Objects Crystal Reports XI Professional 0
Microsoft Visual Studio .NET 2003
Business Objects Crystal Reports for Visual Studio .NET 2005 10.2
Microsoft Visual Studio 2005 SP1
Microsoft Visual Studio .NET 2002 SP1
Business Objects Crystal Enterprise 10.0
Solution:
The vendor has released updates to address this issue. Please see the referenced advisories for more information.
Business Objects Crystal Reports for Visual Studio .NET 2003 0
-
Business Objects crnet11win_en.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/crnet11win_en.zip
Business Objects Crystal Reports for Visual Studio .NET 2002 0
-
Business Objects crnet10win_en.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/crnet10win_en.zip
Microsoft Visual Studio 2005
-
Microsoft VS80-KB937060-X86.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=21073CC2-919C -40DF-8EBB-AA3DB06050D2
Business Objects Crystal Reports XI Professional 0
-
Business Objects commonXIwin_chf.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/commonXIwin_chf.zip
Microsoft Visual Studio .NET 2003
-
Microsoft VS7.1-KB937058-X86-INTL.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=D612AD41-5A0D -4E13-99EA-D6A5589786D6 -
Microsoft VS7.1sp1-KB937059-X86-INTL.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=0B10B04B-932C -4BFF-9CBC-B3EEB15064B1
Business Objects Crystal Reports for Visual Studio .NET 2005 10.2
-
Business Objects crnet20win32x86_en_chf.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/crnet20win32x86_en_chf.zip -
Business Objects crnet20win64amd_en_chf.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/crnet20win64amd_en_chf.zip
Microsoft Visual Studio 2005 SP1
-
Microsoft VS80sp1-KB937061-X86.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=967D43C8-EFBA -4221-BEB0-981E7DEEF33A
Microsoft Visual Studio .NET 2002 SP1
-
Microsoft VS7.0sp1-KB937057-X86.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2608C83B-E1B2 -4449-9A0E-1E566AAC3D76
Business Objects Crystal Enterprise 10.0
-
Business Objects common10win_en.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/common10win_en.zip -
Business Objects cr10win_en.zip
ftp://ftp1.businessobjects.com/outgoing/CHF/cr10win_en.zip