Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.
References
Configurations
History
21 Nov 2024, 00:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064627.html - Patch | |
References | () http://osvdb.org/38697 - | |
References | () http://securityreason.com/securityalert/2898 - | |
References | () http://www.pirs.si/slo/index.php?dep_id=29&help_id=60 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/35388 - |
Information
Published : 2007-07-17 00:30
Updated : 2024-11-21 00:34
NVD link : CVE-2007-3815
Mitre link : CVE-2007-3815
CVE.ORG link : CVE-2007-3815
JSON object : View
Products Affected
republike_slovenije
- pirs
CWE