PT-2017-16841 · 3S Smart Software Solutions · Codesys Web Server

Publicado

2017-05-19

·

Atualizado

2019-10-09

·

CVE-2017-6025

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Web Server versions 2.3 and prior
Description A Stack Buffer Overflow issue was discovered in the CODESYS Web Server, which is part of the CODESYS WebVisu web browser visualization software. This issue can be exploited by providing overly long strings to functions that handle XML, potentially allowing an attacker to crash the application or run arbitrary code, as the function does not verify string size before copying to memory.
Recommendations For CODESYS Web Server versions 2.3 and prior, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting input to functions that handle XML to prevent overly long strings from being processed.

Correção

Stack Overflow

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6025

Produtos afetados

Codesys Web Server