Информационная безопасность
[RU] switch to
English Version



CVECVE-2009-1515
СтатусCandidate
ОписаниеHeap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file.  NOTE: some of these details are obtained from third party information.
ВажностьMedium
CVSS score6,8
CVSS vector(AV:N/AC:M/Au:N/C:P/I:P/A:P)
PhaseAssigned (13.11.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1515
ReferencesBID : 34745
 CONFIRM : ftp://ftp.astron.com/pub/file/file-5.01.tar.gz
 MISC : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=5...
 MISC : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=5...
 OSVDB : 54100
 SECUNIA : 34881
SecurityVulns:Переполнение буфера в утилите file

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server