First published: Thu May 31 2007(Updated: )
The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Withsecure F-Secure Policy Manager | <=7.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2964 is classified as a denial of service vulnerability, leading to application crashes.
The recommended fix for CVE-2007-2964 is to upgrade to a version of F-Secure Policy Manager Server later than 7.00.
F-Secure Policy Manager Server versions 7.00 and earlier are affected by CVE-2007-2964.
Yes, CVE-2007-2964 can be exploited by remote attackers through specially crafted URLs with NTFS reserved words in filenames.
CVE-2007-2964 can cause a denial of service, resulting in crashes of the F-Secure Policy Manager Server application.