CVE-2012-4341: Buffer Overflow
Multiple stack-based buffer overflows in msgserver.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) long parameter value, (2) crafted string size field, or (3) long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4341?
CVE-2012-4341 is considered critical due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2012-4341?
To fix CVE-2012-4341, apply the latest patches and updates provided by SAP for affected versions of NetWeaver ABAP.
What are the affected versions for CVE-2012-4341?
CVE-2012-4341 affects SAP NetWeaver ABAP versions 7.0, 7.02-sp6, and 7.03-sp4.
Can CVE-2012-4341 be exploited remotely?
Yes, CVE-2012-4341 can be exploited remotely by sending specially crafted parameters to msg_server.exe.
What impact does CVE-2012-4341 have on systems?
Exploitation of CVE-2012-4341 can lead to system crashes, code execution, and unauthorized access.