CVE-2005-1394: High severity Esri ArcInfo Workstation vulnerability
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1394?
CVE-2005-1394 is considered to have a moderate severity level due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2005-1394?
To fix CVE-2005-1394, you should upgrade to a patched version of ArcGIS or ArcInfo Workstation that addresses this vulnerability.
Who is affected by CVE-2005-1394?
CVE-2005-1394 affects local users of ESRI ArcInfo Workstation version 9.0 and ArcGIS version 9.0.
What type of attack does CVE-2005-1394 involve?
CVE-2005-1394 involves a format string vulnerability that can be exploited through malicious format specifiers in environment variables.
What are the potential consequences of CVE-2005-1394?
The exploitation of CVE-2005-1394 can lead to unauthorized privilege escalation, allowing attackers to execute arbitrary code with elevated permissions.