Skip to main content

CVE-2007-3815

Severity Medium
Score 4.9/10

Summary

Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.

  • LOW
  • LOCAL
  • NONE
  • NONE
  • NONE
  • COMPLETE

References

Advisory Timeline

  • Published