PT-2017-16841 · 3S Smart Software Solutions · Codesys Web Server
Publicado
2017-05-19
·
Atualizado
2019-10-09
·
CVE-2017-6025
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CODESYS Web Server versions 2.3 and prior
Description
A Stack Buffer Overflow issue was discovered in the CODESYS Web Server, which is part of the CODESYS WebVisu web browser visualization software. This issue can be exploited by providing overly long strings to functions that handle XML, potentially allowing an attacker to crash the application or run arbitrary code, as the function does not verify string size before copying to memory.
Recommendations
For CODESYS Web Server versions 2.3 and prior, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting input to functions that handle XML to prevent overly long strings from being processed.
Correção
Stack Overflow
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Codesys Web Server