PT-2020-3993 · Fuji Electric · V-Server Lite

Kimiya

·

Published

2020-04-09

·

Updated

2020-04-13

·

CVE-2020-10646

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fuji Electric V-Server Lite versions prior to 4.0.9.0
Description: The issue is related to a heap-based buffer overflow when parsing VPR files. This occurs because the buffer allocated to read data is too small. Exploitation of this issue may allow an attacker to execute arbitrary code on the target system by opening a specially crafted malicious VPR file.
Recommendations: For versions prior to 4.0.9.0, update to version 4.0.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to VPR files or avoiding the use of VPR file parsing functionality until a patch is applied.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04387
CVE-2020-10646
ZDI-20-451
ZDI-20-452

Affected Products

V-Server Lite