First published: Wed Jun 06 2007(Updated: )
Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Numara Asset Manager | =8.0 | |
Symantec Discovery | =6.5 | |
Centennial Discovery | =2006_featurepack1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2514 has a high severity rating due to its potential for remote code execution.
CVE-2007-2514 affects multiple products including Symantec Discovery 6.5, Numara Asset Manager 8.0, and Centennial Discovery 2006 Feature Pack.
To fix CVE-2007-2514, update the affected software to the latest version provided by the vendor.
CVE-2007-2514 can be exploited by a remote attacker sending a specially crafted long request to the vulnerable application.
As a workaround for CVE-2007-2514, restrict access to the affected software or monitor network traffic for suspicious requests.