Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
BID:24824
Info
Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
| Bugtraq ID: | 24824 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2007 12:00AM |
| Updated: | Jul 09 2007 12:00AM |
| Credit: | Michal Bucko is credited with the discovery of this vulnerability. |
| Vulnerable: |
Computer Associates ERWin Process Modeler 7.1 |
| Not Vulnerable: | |
Discussion
Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
Computer Associates ERwin Process Modeler is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts likely result in a denial-of-service condition.
This issue affects ERwin Process Modeler 7.1; other versions may also be affected.
Computer Associates ERwin Process Modeler is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts likely result in a denial-of-service condition.
This issue affects ERwin Process Modeler 7.1; other versions may also be affected.
Exploit / POC
Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Computer Associates ERwin Process Modeler MERGEOLF.EXE Buffer Overflow Vulnerability
References:
References:
- AllFusion LICRCMD.EXE Buffer Overflow Issue (Michal Bucko)
- Computer Associates AllFusion Process Modeler Home Page (Computer Associates)