Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
BID:66130
Info
Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 66130 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0781 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2014 12:00AM |
| Updated: | Oct 13 2014 12:01AM |
| Credit: | juan vazquez |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
Yokogawa CENTUM CS3000 is prone to a heap-based buffer-overflow vulnerability.
Successful exploits will allow attackers to crash the affected application, resulting in a denial-of-service condition. Due to the nature of this issue, code execution is also possible.
Yokogawa CENTUM CS3000 R3.08.50 is vulnerable; other versions may also be affected.
Yokogawa CENTUM CS3000 is prone to a heap-based buffer-overflow vulnerability.
Successful exploits will allow attackers to crash the affected application, resulting in a denial-of-service condition. Due to the nature of this issue, code execution is also possible.
Yokogawa CENTUM CS3000 R3.08.50 is vulnerable; other versions may also be affected.
Exploit / POC
Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can exploit this issue using readily available tools.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
References:
References: