CVE-2007-6349: High severity Perforce P4Web vulnerability
Published Dec 20, 2007
·Updated
P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-Length greater than 0.
Affected Software
2 affected components
Perforce P4Web=2006.2
Perforce P4Web=2006.1
Remediation
Patch Available
Event History
Dec 20, 2007
CVE Published
11:46 PM
Dec 21, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6349?
CVE-2007-6349 is classified as a denial of service vulnerability that can cause high CPU consumption.
2
How do I fix CVE-2007-6349?
To fix CVE-2007-6349, upgrade to a newer version of Perforce P4Web that has mitigations for this vulnerability.
3
What systems are affected by CVE-2007-6349?
CVE-2007-6349 affects Perforce P4Web versions 2006.1 and 2006.2 running on Windows.
4
What type of attack does CVE-2007-6349 enable?
CVE-2007-6349 enables remote attackers to perform denial of service attacks through specific HTTP requests.
5
Is CVE-2007-6349 a local or remote vulnerability?
CVE-2007-6349 is a remote vulnerability, allowing attackers to exploit it over the network.