PT-2005-2003 · Honeywell · Rumba
Bahaa Naamneh
·
Publicado
2005-04-05
·
Atualizado
2017-07-11
·
CVE-2005-0979
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RUMBA versions 7.3 and earlier
Description
The issue is related to multiple buffer overflows that can be triggered by remote attackers using crafted values in a profile file. This can lead to a denial of service and potentially allow the execution of arbitrary code. An example of such exploitation is through the use of a long
SysName field.Recommendations
For versions 7.3 and earlier, consider applying configuration changes to restrict access to profile files until a fix is available. As a temporary workaround, restrict the length of the
SysName field to prevent buffer overflows.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rumba