CVE-2006-0089: Buffer Overflow
Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0089?
CVE-2006-0089 is classified as potentially critical due to its ability to cause application crashes and possibly allow remote code execution.
How do I fix CVE-2006-0089?
To fix CVE-2006-0089, upgrade to a version of ESRI ArcPad later than 7.0.0.156, as this vulnerability has been addressed in subsequent releases.
What impact does CVE-2006-0089 have on users?
CVE-2006-0089 can lead to denial of service, impacting user access to the application, and potentially allows attackers to execute arbitrary code.
Which versions of ESRI ArcPad are affected by CVE-2006-0089?
ESRI ArcPad versions up to and including 7.0.0.156 are affected by CVE-2006-0089.
Who can exploit CVE-2006-0089?
Remote attackers can exploit CVE-2006-0089 by sending crafted .amp files containing a long COORDSYS string to vulnerable ESRI ArcPad installations.