PT-2017-16841 · 3S Smart Software Solutions · Codesys Web Server

Published

2017-05-19

·

Updated

2019-10-09

·

CVE-2017-6025

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Web Server versions 2.3 and prior
Description A Stack Buffer Overflow issue was discovered in the CODESYS Web Server, which is part of the CODESYS WebVisu web browser visualization software. This issue can be exploited by providing overly long strings to functions that handle XML, potentially allowing an attacker to crash the application or run arbitrary code, as the function does not verify string size before copying to memory.
Recommendations For CODESYS Web Server versions 2.3 and prior, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting input to functions that handle XML to prevent overly long strings from being processed.

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6025

Affected Products

Codesys Web Server