Back to search
CVE-2010-3032
Published: Aug 17, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GIOP packet with a crafted size, which triggers a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2010-2074
vdb-entry
x_refsource_VUPEN
http://dvlabs.tippingpoint.com/advisory/TPTI-10-07
x_refsource_MISC
sap-crystal-giop-bo(61065)
vdb-entry
x_refsource_XF
40960
third-party-advisory
x_refsource_SECUNIA
https://service.sap.com/sap/support/notes/1473327
x_refsource_MISC
42374
vdb-entry
x_refsource_BID
20100811 ZDI-10-151: SAP Crystal Reports 2008 GIOP Message Size Integer Overflow Remote Code Execution Vulnerability
mailing-list
x_refsource_BUGTRAQ
1024334
vdb-entry
x_refsource_SECTRACK
67080
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now