PT-2018-10021 · Cncsoft+1 · Cncsoft+1

Natnael Samson

+1

·

Publicado

2018-08-13

·

Atualizado

2020-08-31

·

CVE-2018-10636

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CNCSoft versions 1.00.83 and prior ScreenEditor versions 1.00.54 and prior
Description The software has multiple stack-based buffer overflow issues due to inadequate user input validation before copying data from project files onto the stack. This could cause the software to crash and may allow an attacker to gain remote code execution with administrator privileges if exploited.
Recommendations For CNCSoft versions 1.00.83 and prior, update to a version later than 1.00.83 to resolve the issue. For ScreenEditor versions 1.00.54 and prior, update to a version later than 1.00.54 to resolve the issue. As a temporary workaround, consider disabling the use of DPB files in the ScreenEditor until a patch is available. Restrict access to the ScreenEditor to minimize the risk of exploitation.

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10636
ZDI-18-1070
ZDI-18-1071
ZDI-18-979
ZDI-18-980
ZDI-18-981
ZDI-18-982
ZDI-18-983
ZDI-18-984
ZDI-18-985
ZDI-18-986

Produtos afetados

Cncsoft
Screeneditor