First published: Wed May 16 2007(Updated: )
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | <=3.1.0 | |
Caucho Resin | <=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2439 is classified as a high severity vulnerability due to its potential to cause a denial of service.
The best way to address CVE-2007-2439 is to upgrade to a version of Caucho Resin that is later than 3.1.0.
CVE-2007-2439 affects Caucho Resin Professional 3.1.0 and all earlier versions for Windows.
CVE-2007-2439 can be exploited by remote attackers to cause a device hang and gain unauthorized access to data.
Yes, CVE-2007-2439 can be exploited remotely through the use of a DOS device name with an arbitrary extension.