Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
BID:46939
Info
Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
| Bugtraq ID: | 46939 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2011 12:00AM |
| Updated: | Mar 19 2015 09:13AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
ICONICS, Inc. GENESIS64 10.51 ICONICS, Inc. GENESIS32 9.21.201.01 ICONICS, Inc. GENESIS32 9.21 |
| Not Vulnerable: | |
Discussion
Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
Iconics GENESIS32 and GENESIS64 are prone to multiple security vulnerabilities including multiple memory-corruption vulnerabilities and multiple integer-overflow vulnerabilities because they fail to properly validate user-supplied input.
Successful exploits may allow the attacker to execute arbitrary code in the context of the application. Failed exploit attempts will likely result in denial-of-service conditions.
The following versions are vulnerable; other versions may also be affected:
GENESIS32 9.21
GENESIS64 10.51
Iconics GENESIS32 and GENESIS64 are prone to multiple security vulnerabilities including multiple memory-corruption vulnerabilities and multiple integer-overflow vulnerabilities because they fail to properly validate user-supplied input.
Successful exploits may allow the attacker to execute arbitrary code in the context of the application. Failed exploit attempts will likely result in denial-of-service conditions.
The following versions are vulnerable; other versions may also be affected:
GENESIS32 9.21
GENESIS64 10.51
Exploit / POC
Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
The following exploit code and proofs of concept are available:
The following exploit code and proofs of concept are available:
Solution / Fix
Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Iconics GENESIS32 and GENESIS64 Multiple Security Vulnerabilities
References:
References:
- genesis_1-adv (Luigi Auriemma)
- genesis_10-adv (Luigi Auriemma)
- genesis_11-adv (Luigi Auriemma)
- genesis_12-adv (Luigi Auriemma)
- genesis_13-adv (Luigi Auriemma)
- genesis_2-adv (Luigi Auriemma)
- genesis_3-adv (Luigi Auriemma)
- genesis_4-adv (Luigi Auriemma)
- genesis_5-adv (Luigi Auriemma)
- genesis_6-adv (Luigi Auriemma)
- genesis_7-adv (Luigi Auriemma)
- genesis_8-adv (Luigi Auriemma)
- genesis_9-adv (Luigi Auriemma)
- GENESIS32 Homepage (ICONICS Inc)
- GENESIS64 Homepage (ICONICS Inc)
- Vulnerabilities in some SCADA server softwares (Luigi Auriemma
)