First published: Thu Jan 05 2006(Updated: )
Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Arcpad | <=7.0.0.156 | |
ESRI ArcPad | <=7.0.0.156 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0089 is classified as potentially critical due to its ability to cause application crashes and possibly allow remote code execution.
To fix CVE-2006-0089, upgrade to a version of ESRI ArcPad later than 7.0.0.156, as this vulnerability has been addressed in subsequent releases.
CVE-2006-0089 can lead to denial of service, impacting user access to the application, and potentially allows attackers to execute arbitrary code.
ESRI ArcPad versions up to and including 7.0.0.156 are affected by CVE-2006-0089.
Remote attackers can exploit CVE-2006-0089 by sending crafted .amp files containing a long COORDSYS string to vulnerable ESRI ArcPad installations.