AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
BID:49606
Info
AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 49606 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3492 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2011 12:00AM |
| Updated: | Sep 22 2011 04:00PM |
| Credit: | Luigi Auriemma |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
AzeoTech DAQFactory is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
DAQFactory 5.85 build 1853 is vulnerable; other versions may also be affected.
AzeoTech DAQFactory is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
DAQFactory 5.85 build 1853 is vulnerable; other versions may also be affected.
Exploit / POC
AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
AzeoTech DAQFactory NETB Datagram Parsing Buffer Overflow Vulnerability
References:
References:
- AzeoTech Homepage (AzeoTech)
- DAQFactory Buffer Overfflow Vulnerabiltiy (Luigi Auriemma)
- ICSA-11-264-01�??AZEOTECH DAQFACTORY STACK OVERFLOW (CERT)