PT-2019-18149 · Wecon · Wecon Levistudiou

Mat Powell

+2

·

Published

2019-01-29

·

Updated

2020-10-05

·

CVE-2019-6537

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WECON LeviStudioU versions 1.8.56 and prior
Description The issue arises from multiple stack-based buffer overflow vulnerabilities when parsing strings within project files. The process fails to properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This can be leveraged by an attacker to execute code under the context of the current process.
Recommendations For WECON LeviStudioU versions 1.8.56 and prior, update to a version later than 1.8.56 to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6537
ZDI-19-143
ZDI-19-144
ZDI-19-145
ZDI-19-151
ZDI-19-152
ZDI-19-153
ZDI-19-154
ZDI-19-155
ZDI-19-156
ZDI-19-764

Affected Products

Wecon Levistudiou