WECON LeviStudioU Multiple Buffer Overflow Vulnerabilities
BID:104935
CVE-2018-10602 | CVE-2018-10606 |Info
WECON LeviStudioU Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 104935 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2018-10602 CVE-2018-10606 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2018 12:00AM |
| Updated: | Jul 31 2018 12:00AM |
| Credit: | NSFOCUS security team and Ghirmay Desta worked with Mat Powell of Trend Micro�??s Zero Day Initiative. |
| Vulnerable: |
WECON LeviStudioU 1.8.44 WECON LeviStudioU 1.8.29 |
| Not Vulnerable: | |
Discussion
WECON LeviStudioU Multiple Buffer Overflow Vulnerabilities
WECON LeviStudioU is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied string size before copying it to an insufficiently sized memory buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
WECON LeviStudioU versions 1.8.29 and 1.8.44 are vulnerable.
WECON LeviStudioU is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied string size before copying it to an insufficiently sized memory buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
WECON LeviStudioU versions 1.8.29 and 1.8.44 are vulnerable.