CVE
- Id
- 20237
- CVE No.
- CVE-2006-4133
- Status
- Candidate
- Description
- Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long portwatcher argument, which triggers the overflow during error message construction when the _snprintf function returns a negative value that is used in a memcpy operation.
- Phase
- Assigned (20060814)
- Votes
- None (candidate not yet proposed)
- Comments