First published: Wed Jul 11 2007(Updated: )
Buffer overflow in LICRCMD.EXE in CA ERwin Process Modeler (formerly AllFusion Process Modeler) 7.1 allows attackers to execute arbitrary code via a long filename. NOTE: the researcher does not suggest any circumstances in which the filename would come from an untrusted source, and therefore perhaps the issue does not cross privilege boundaries and should not be included in CVE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Erwin Process Modeler | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3695 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2007-3695, upgrade CA ERwin Process Modeler to a version that is not affected by this vulnerability.
CVE-2007-3695 affects CA ERwin Process Modeler version 7.1.
An attacker can exploit CVE-2007-3695 to execute arbitrary code through a specially crafted long filename.
CVE-2007-3695 may not be exploitable remotely as the vulnerability involves local filename handling.