GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
BID:61469
Info
GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 61469 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-2785 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2013 12:00AM |
| Updated: | Jul 26 2013 12:00AM |
| Credit: | ZombiE and amisto0x07 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
GE Proficy CIMPLICITY is prone to multiple remote stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to cause the application to crash or execute arbitrary code in the context of the affected application.
GE Proficy CIMPLICITY is prone to multiple remote stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to cause the application to crash or execute arbitrary code in the context of the affected application.
Exploit / POC
GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
GE Proficy CIMPLICITY 'CimWebServer' Remote Stack Buffer Overflow Vulnerabilities
References:
References: