PT-2018-14278 · Delta Industrial Automation · Tpeditor
Ariele Caltabiano
+2
·
Publicado
2018-10-11
·
Atualizado
2020-09-18
·
CVE-2018-17929
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Industrial Automation TPEditor versions 1.90 and prior
Description
The issue is related to multiple stack-based buffer overflow vulnerabilities that can be exploited by processing specially crafted project files. These vulnerabilities may allow an attacker to remotely execute arbitrary code due to a lack of user input validation before copying data from project files onto the stack.
Recommendations
For versions 1.90 and prior, update to a version later than 1.90 to resolve the issue.
As a temporary workaround, consider restricting the processing of project files from untrusted sources to minimize the risk of exploitation.
Correção
Stack Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tpeditor