Bug: Openedge _mprosrv buffer overflow ( Ascii Version )

Search:
WLB2

CVE WLB2

Openedge _mprosrv buffer overflow

Published
Credit
Risk
2007.07.03
suresync
High
CWE
CVE
Local
Remote
CWE-119
CVE-2007-3491
Yes
No

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

There is a potential for a buffer overflow in the database executable _mprosrv while reading a TCP/IP message that is
incorrectly formatted. To avoid this problem, additional checking has been added to the _mprosrv executable that will
prevent incorrectly formatted messages from causing buffer overflows.

Bug# OE00148128 has been addressed in Progress 9.1E0422 and OpenEdge 10.1B01. The 9.1E0422 version of this fix requires
that 9.1E04 be installed prior to this fix being applied to the Progress installation. These versions of Progress are
available for download from the OpenEdge Download Center.

ASCII VERSION

Copyright 2013, cxsecurity.com
Ascii Version