Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
BID:24817
Info
Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
| Bugtraq ID: | 24817 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3695 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Michal Bucko is credited with the discovery of this vulnerability. |
| Vulnerable: |
Computer Associates ERWin Process Modeler 7.1 |
| Not Vulnerable: | |
Discussion
Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
Computer Associates AllFusion Process Modeler is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects version AllFusion Process Modeler 7.1; other versions may also be affected.
Computer Associates AllFusion Process Modeler is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects version AllFusion Process Modeler 7.1; other versions may also be affected.
Exploit / POC
Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Computer Associates AllFusion Process Modeler Buffer Overflow Vulnerability
References:
References:
- AllFusion LICRCMD.EXE Buffer Overflow Issue (Michal Bucko)
- Computer Associates AllFusion Process Modeler Home Page (Computer Associates)