CVE-2005-2297: Buffer Overflow
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2297?
CVE-2005-2297 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2005-2297?
To mitigate CVE-2005-2297, upgrade Sybase EAServer to version 5.2.1 or higher, as it contains the necessary security patches.
Who is affected by CVE-2005-2297?
CVE-2005-2297 affects authenticated remote users of Sybase EAServer versions 4.2.5 to 5.2.
What kind of attack can exploit CVE-2005-2297?
CVE-2005-2297 can be exploited through a stack-based buffer overflow by sending a large JavaScript parameter.
Is CVE-2005-2297 still a concern for users today?
While CVE-2005-2297 was identified in 2005, users of affected EAServer versions may still be at risk if they have not applied the necessary updates.