PT-2018-9997 · Wecon · Wecon Levistudiou

Publicado

2018-07-26

·

Atualizado

2020-08-28

·

CVE-2018-10606

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: WECON LeviStudio versions 1.8.29 through 1.8.44
Description: The issue is related to multiple heap-based buffer overflow vulnerabilities that can be exploited when the application processes specially crafted project files. These vulnerabilities can lead to remote code execution. The affected components include TIFF parsing, PartInfo PartName, screenhelper ScrnName, screendata IndirectAddrR, PartInfo WriteAddr, Datalogtool file creation data, screendata Key ASCIIKey, General WordAddr, figure FigureFile, stringlib Content, screenhelper ScrnFile, addresslib Port, and addresslib Name.
Recommendations: For WECON LeviStudio versions 1.8.29 through 1.8.44, consider disabling the processing of specially crafted project files until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using the affected functions and parameters in the application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10606
ZDI-18-1089
ZDI-18-808
ZDI-18-809
ZDI-18-814
ZDI-18-815
ZDI-18-816
ZDI-18-866
ZDI-18-867
ZDI-18-869
ZDI-18-872
ZDI-18-873
ZDI-18-990
ZDI-18-992

Produtos afetados

Wecon Levistudiou