Business Objects Crystal Reports XI Professional - File Handling Buffer Overflow

Author: LSsec.com
type: remote
platform: windows
port: 
date_added: 2006-11-23  
date_updated: 2013-10-28  
verified: 1  
codes: CVE-2006-6133;OSVDB-31704  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 29171.txt  
source: https://www.securityfocus.com/bid/21261/info

Business Objects Crystal Reports XI Professional is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

An atacker may exploit this issue by enticing a victim user into opening a malicious document file, resulting in the execution of arbitrary code with privileges of the vulnerable application. Failed exploit attemtps will likely result in denial-of-service conditions.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/29171.rpt