PT-2018-14278 · Delta Industrial Automation · Tpeditor

Ariele Caltabiano

+2

·

Publicado

2018-10-11

·

Atualizado

2020-09-18

·

CVE-2018-17929

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Industrial Automation TPEditor versions 1.90 and prior
Description The issue is related to multiple stack-based buffer overflow vulnerabilities that can be exploited by processing specially crafted project files. These vulnerabilities may allow an attacker to remotely execute arbitrary code due to a lack of user input validation before copying data from project files onto the stack.
Recommendations For versions 1.90 and prior, update to a version later than 1.90 to resolve the issue. As a temporary workaround, consider restricting the processing of project files from untrusted sources to minimize the risk of exploitation.

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17929
ZDI-18-1236
ZDI-18-1238
ZDI-18-1240
ZDI-18-1241
ZDI-18-1243
ZDI-18-1244

Produtos afetados

Tpeditor