Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
References
Link | Resource |
---|---|
http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt | Patch Third Party Advisory |
http://securitytracker.com/id?1013852 | Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory |
http://secunia.com/advisories/15196 | Broken Link |
http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015 | Vendor Advisory |
http://marc.info/?l=full-disclosure&m=111489411524630&w=2 | Mailing List Third Party Advisory |
Configurations
History
11 Jul 2024, 18:03
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-134 | |
CPE | ||
References | (FULLDISC) http://marc.info/?l=full-disclosure&m=111489411524630&w=2 - Mailing List, Third Party Advisory | |
References | (MISC) http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt - Patch, Third Party Advisory | |
References | (CONFIRM) http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015 - Vendor Advisory | |
References | (SECTRACK) http://securitytracker.com/id?1013852 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory | |
References | (SECUNIA) http://secunia.com/advisories/15196 - Broken Link |
Information
Published : 2005-05-03 04:00
Updated : 2024-07-11 18:03
NVD link : CVE-2005-1394
Mitre link : CVE-2005-1394
JSON object : View
Products Affected
esri
- arcinfo_workstation
CWE
CWE-134
Use of Externally-Controlled Format String