PT-2020-3993 · Fuji Electric · V-Server Lite
Kimiya
·
Published
2020-04-09
·
Updated
2020-04-13
·
CVE-2020-10646
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Fuji Electric V-Server Lite versions prior to 4.0.9.0
Description:
The issue is related to a heap-based buffer overflow when parsing VPR files. This occurs because the buffer allocated to read data is too small. Exploitation of this issue may allow an attacker to execute arbitrary code on the target system by opening a specially crafted malicious VPR file.
Recommendations:
For versions prior to 4.0.9.0, update to version 4.0.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to VPR files or avoiding the use of VPR file parsing functionality until a patch is applied.
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
V-Server Lite