PT-2017-15530 · National Instruments · Labview
Publicado
2017-03-31
·
Atualizado
2022-04-19
·
CVE-2017-2775
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LabVIEW versions prior to 2015 SP1 f7 Patch
LabVIEW versions prior to 2016 f2 Patch
Description
A memory corruption issue exists in the LvVariantUnflatten functionality. It can be triggered by a specially crafted VI file, causing a user-controlled value to be used as a loop terminator, which results in internal heap corruption. This could potentially lead to remote code execution if an attacker-controlled VI file is used to exploit the issue.
Recommendations
For LabVIEW versions prior to 2015 SP1 f7 Patch, update to 2015 SP1 f7 Patch or later to resolve the issue.
For LabVIEW versions prior to 2016 f2 Patch, update to 2016 f2 Patch or later to resolve the issue.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Labview