CVE-2017-2779
Summary
| CVE | CVE-2017-2779 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-05 18:29:00 UTC |
| Updated | 2022-04-19 19:15:00 UTC |
| Description | An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condition resulting in an arbitrary null write. An attacker controlled VI file can be used to trigger this vulnerability and can potentially result in code execution. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ni | Labview | 2014 | All | All | All |
| Application | Ni | Labview | 2015 | All | All | All |
| Application | Ni | Labview | 2016 | All | All | All |
| Application | Ni | Labview | 2017 | All | All | All |
| Application | Ni | Labview | 2014 | All | All | All |
| Application | Ni | Labview | 2015 | All | All | All |
| Application | Ni | Labview | 2016 | All | All | All |
| Application | Ni | Labview | 2017 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| National Instruments LabVIEW CVE-2017-2779 Memory Corruption Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| TALOS-2017-0273 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | www.talosintelligence.com | Exploit, Third Party Advisory, VDB Entry |
| Incomplete RSRC Validation in LabVIEW - National Instruments | CONFIRM | www.ni.com | Mitigation, Vendor Advisory |
| 0patch Blog: 0patching the RSRC Arbitrary NULL Write Vulnerability in LabVIEW (CVE-2017-2779) | MISC | 0patch.blogspot.com | Exploit, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.