PT-2018-9997 · Wecon · Wecon Levistudiou

Published

2018-07-26

·

Updated

2020-08-28

·

CVE-2018-10606

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: WECON LeviStudio versions 1.8.29 through 1.8.44
Description: The issue is related to multiple heap-based buffer overflow vulnerabilities that can be exploited when the application processes specially crafted project files. These vulnerabilities can lead to remote code execution. The affected components include TIFF parsing, PartInfo PartName, screenhelper ScrnName, screendata IndirectAddrR, PartInfo WriteAddr, Datalogtool file creation data, screendata Key ASCIIKey, General WordAddr, figure FigureFile, stringlib Content, screenhelper ScrnFile, addresslib Port, and addresslib Name.
Recommendations: For WECON LeviStudio versions 1.8.29 through 1.8.44, consider disabling the processing of specially crafted project files until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using the affected functions and parameters in the application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10606
ZDI-18-1089
ZDI-18-808
ZDI-18-809
ZDI-18-814
ZDI-18-815
ZDI-18-816
ZDI-18-866
ZDI-18-867
ZDI-18-869
ZDI-18-872
ZDI-18-873
ZDI-18-990
ZDI-18-992

Affected Products

Wecon Levistudiou