First published: Mon Jul 30 2007(Updated: )
Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BakBone NetVault Reporter | <=3.5update3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3911 is considered a high severity vulnerability due to the risk of remote code execution.
To fix CVE-2007-3911, you should update BakBone NetVault Reporter to version 3.5 Update 4 or later.
The potential impacts of CVE-2007-3911 include unauthorized remote code execution which could compromise system integrity.
CVE-2007-3911 affects BakBone NetVault Reporter versions prior to 3.5 Update 4.
CVE-2007-3911 exploits the system through multiple heap-based buffer overflows triggered by long filename arguments in HTTP requests.