10

CVE-2007-1666

The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DatarescueIda Pro Version5.0
DatarescueIda Pro Version5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.15% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://labs.idefense.com/intelligence/vulnerabilities/
http://secunia.com/advisories/24635
Vendor Advisory
http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip
Patch
http://www.osvdb.org/33523
http://www.securityfocus.com/bid/23114
http://www.securitytracker.com/id?1017815
http://www.vupen.com/english/advisories/2007/1089
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/33190