First published: Mon May 02 2005(Updated: )
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ESRI ArcInfo Workstation | =9.0 | |
Esri ArcGIS | =9.0 | |
Esri ArcInfo | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1394 is considered to have a moderate severity level due to its potential to allow local users to gain elevated privileges.
To fix CVE-2005-1394, you should upgrade to a patched version of ArcGIS or ArcInfo Workstation that addresses this vulnerability.
CVE-2005-1394 affects local users of ESRI ArcInfo Workstation version 9.0 and ArcGIS version 9.0.
CVE-2005-1394 involves a format string vulnerability that can be exploited through malicious format specifiers in environment variables.
The exploitation of CVE-2005-1394 can lead to unauthorized privilege escalation, allowing attackers to execute arbitrary code with elevated permissions.