PT-2005-2003 · Honeywell · Rumba
Bahaa Naamneh
·
Published
2005-04-05
·
Updated
2017-07-11
·
CVE-2005-0979
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RUMBA versions 7.3 and earlier
Description
The issue is related to multiple buffer overflows that can be triggered by remote attackers using crafted values in a profile file. This can lead to a denial of service and potentially allow the execution of arbitrary code. An example of such exploitation is through the use of a long
SysName field.Recommendations
For versions 7.3 and earlier, consider applying configuration changes to restrict access to profile files until a fix is available. As a temporary workaround, restrict the length of the
SysName field to prevent buffer overflows.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rumba