Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ziad Badawi

Pesquisador deTrend Micro’s Zero Day Initiative
#33982de 53,639
7.8CVSS total
Vulnerabilidades · 1
PT-2019-18149
7.8
2019-01-29
Wecon · Wecon Levistudiou · CVE-2019-6537
**Name of the Vulnerable Software and Affected Versions** WECON LeviStudioU versions 1.8.56 and prior **Description** The issue arises from multiple stack-based buffer overflow vulnerabilities when parsing strings within project files. The process fails to properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This can be leveraged by an attacker to execute code under the context of the current process. **Recommendations** For WECON LeviStudioU versions 1.8.56 and prior, update to a version later than 1.8.56 to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.