CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference.
Link | Tags |
---|---|
http://osvdb.org/39596 | vdb entry |
http://www.eleytt.com/advisories/eleytt_ALLFUSIONDATAMODEL.pdf | vendor advisory |
http://www.securityfocus.com/bid/24814 | vdb entry |