Vulnerability Description
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esri | Arcinfo Workstation | 9.0 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/15196Broken Link
- http://securitytracker.com/id?1013852Broken LinkPatchThird Party Advisory
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PIDVendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txtPatchThird Party Advisory
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2Mailing ListThird Party Advisory
- http://secunia.com/advisories/15196Broken Link
- http://securitytracker.com/id?1013852Broken LinkPatchThird Party Advisory
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PIDVendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txtPatchThird Party Advisory
FAQ
What is CVE-2005-1394?
CVE-2005-1394 is a vulnerability with a CVSS score of 7.2 (HIGH). Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) loc...
How severe is CVE-2005-1394?
CVE-2005-1394 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1394?
Check the references section above for vendor advisories and patch information. Affected products include: Esri Arcinfo Workstation.