CVE-2008-1411: Input Validation
Published Mar 20, 2008
·Updated
The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.
Affected Software
1 affected component
Acronis Snap Deploy=2.0.0.1076
Event History
Mar 20, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1411?
CVE-2008-1411 is classified as a denial of service vulnerability.
2
How do I fix CVE-2008-1411?
To fix CVE-2008-1411, upgrade Acronis Snap Deploy to version 2.0.0.1077 or later.
3
What systems are affected by CVE-2008-1411?
CVE-2008-1411 affects Acronis Snap Deploy versions up to and including 2.0.0.1076.
4
Can CVE-2008-1411 be exploited remotely?
Yes, CVE-2008-1411 can be exploited remotely through an incomplete TFTP request.
5
What does CVE-2008-1411 do to the affected system?
CVE-2008-1411 can cause the Acronis PXE Server to crash, resulting in a denial of service.