Vulnerability CVE-2007-4027


Published: 2007-07-26   Modified: 2012-02-12

Description:
Buffer overflow in cli32 in Areca CLI 1.72.250 and earlier might allow local users to gain privileges via a long argument. NOTE: this program is not setuid by default, but there are some usage scenarios in which an administrator might make it setuid.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Buffer overflow in Areca CLI, version <= 1.72.250
Sebastian Wolfga...
28.07.2007

Type:

CWE-Other

Vendor: Areca
Product: CLI 
Version: 1.72.250;

CVSS2 => (AV:L/AC:M/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.6/10
10/10
2.7/10
Exploit range
Attack complexity
Authentication
Local
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://securityreason.com/securityalert/2928
http://www.devtarget.org/areca-advisory-07-2007.txt
http://www.securityfocus.com/archive/1/474415/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/35546

Copyright 2019, cxsecurity.com

 

Back to Top