First published: Tue Nov 28 2006(Updated: )
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports XI | ||
Microsoft Visual Studio | =2002 | |
Microsoft Visual Studio | =2002-sp1 | |
Microsoft Visual Studio | =2003 | |
Microsoft Visual Studio | =2003-sp1 | |
Microsoft Visual Studio | =2005 | |
Microsoft Visual Studio | =2005-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6133 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2006-6133, update to the latest version of Crystal Reports or apply any available patches for the affected Microsoft Visual Studio .NET versions.
CVE-2006-6133 affects Crystal Reports XI Professional and several versions of Microsoft Visual Studio .NET from 2002 to 2005.
CVE-2006-6133 is a stack-based buffer overflow vulnerability.
Yes, CVE-2006-6133 can be exploited remotely by user-assisted attackers.