CVE-2007-0042: Infoleak
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0042?
CVE-2007-0042 has a high severity rating due to its potential for unauthorized access to sensitive configuration files.
How do I fix CVE-2007-0042?
To fix CVE-2007-0042, update the Microsoft .NET Framework to a version that addresses this vulnerability.
What are the affected versions in CVE-2007-0042?
CVE-2007-0042 affects Microsoft .NET Framework versions 1.0, 1.1, and 2.0.
Can CVE-2007-0042 be exploited remotely?
Yes, CVE-2007-0042 can be exploited remotely by attackers targeting vulnerable applications.
What types of systems are vulnerable to CVE-2007-0042?
CVE-2007-0042 affects systems running Microsoft Windows 2000, XP, Server 2003, and Vista with the vulnerable versions of .NET Framework.