PT-2005-2003 · Honeywell · Rumba

Bahaa Naamneh

·

Published

2005-04-05

·

Updated

2017-07-11

·

CVE-2005-0979

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RUMBA versions 7.3 and earlier
Description The issue is related to multiple buffer overflows that can be triggered by remote attackers using crafted values in a profile file. This can lead to a denial of service and potentially allow the execution of arbitrary code. An example of such exploitation is through the use of a long SysName field.
Recommendations For versions 7.3 and earlier, consider applying configuration changes to restrict access to profile files until a fix is available. As a temporary workaround, restrict the length of the SysName field to prevent buffer overflows.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0979

Affected Products

Rumba