RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
BID:48492
Info
RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 48492 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2011 12:00AM |
| Updated: | Jun 29 2011 12:00AM |
| Credit: | Dmitriy Pletnev of Secunia Research |
| Vulnerable: |
Rockwell Automation Rockwell OPC Automation 1.1.8.0 Rockwall Automation RSLinx 2.3.1 Build 10 |
| Not Vulnerable: |
Rockwell Automation RSLinx 2.55 |
Discussion
RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
The RSLinx ActiveX control is prone to a remote stack-based buffer-overflow vulnerability that affects the 'RsiOPCAuto.OPCServer' ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
The following products are vulnerable:
Rockwell OPC Automation ActiveX Control version 1.1.8.0
RSLinx 2.3.1 Build 10
The RSLinx ActiveX control is prone to a remote stack-based buffer-overflow vulnerability that affects the 'RsiOPCAuto.OPCServer' ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
The following products are vulnerable:
Rockwell OPC Automation ActiveX Control version 1.1.8.0
RSLinx 2.3.1 Build 10
Exploit / POC
RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
RSLinx OPC Automation ActiveX Control Stack Buffer Overflow Vulnerability
References:
References:
- Secunia Research: RSLinx OPC Automation ActiveX Control Buffer Overflow (Secunia)
- Vendor Homepage (RSLinx Classic)