CVE-2014-5506 Information

Description

Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file.

Reference

http://scn.sap.com/docs/DOC-8218 http://secunia.com/advisories/61016 http://www.securityfocus.com/bid/69557 http://www.zerodayinitiative.com/advisories/ZDI-14-302/ https://service.sap.com/sap/support/notes/1999142

Share on: