Vulnerability Description
Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Republike Slovenije | Pirs | 2007 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064627.htmlPatch
- http://osvdb.org/38697
- http://securityreason.com/securityalert/2898
- http://www.pirs.si/slo/index.php?dep_id=29&help_id=60
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35388
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064627.htmlPatch
- http://osvdb.org/38697
- http://securityreason.com/securityalert/2898
- http://www.pirs.si/slo/index.php?dep_id=29&help_id=60
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35388
FAQ
What is CVE-2007-3815?
CVE-2007-3815 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long ...
How severe is CVE-2007-3815?
CVE-2007-3815 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3815?
Check the references section above for vendor advisories and patch information. Affected products include: Republike Slovenije Pirs.