>> Progress Server and OpenEdge "_mprosrv.exe" Buffer Overflow Vulnerability
Title : Progress Server and OpenEdge "_mprosrv.exe" Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2530 CVE ID : CVE-2007-2417
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-13
Technical Description
A vulnerability has been identified in Progress and OpenEdge, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error within the "_mprosrv.exe" service when processing overly long requests sent to ports 5520/TCP and 5530/TCP, which could be exploited by attackers to crash an affected application or execute arbitrary code via a specially crafted request.