Cogent Real-Time Systems DataHub CVE-2014-3788 Remote Heap Buffer Overflow Vulnerability
BID:67485
Info
Cogent Real-Time Systems DataHub CVE-2014-3788 Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 67485 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3788 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2014 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | Pawel Wylecial |
| Vulnerable: |
Cogentdatahub Cogent DataHub 7.3.4 Cogentdatahub Cogent DataHub 7.3.3 Cogentdatahub Cogent DataHub 7.3.2 Cogentdatahub Cogent DataHub 7.3 |
| Not Vulnerable: |
Cogentdatahub Cogent DataHub 7.3.5 |
Discussion
Cogent Real-Time Systems DataHub CVE-2014-3788 Remote Heap Buffer Overflow Vulnerability
Cogent Real-Time Systems DataHub is prone to a remote heap-based buffer-overflow vulnerability.
Attackers may be able to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Cogent DataHub 7.3.5 are vulnerable.
Cogent Real-Time Systems DataHub is prone to a remote heap-based buffer-overflow vulnerability.
Attackers may be able to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Versions prior to Cogent DataHub 7.3.5 are vulnerable.
Exploit / POC
Cogent Real-Time Systems DataHub CVE-2014-3788 Remote Heap Buffer Overflow Vulnerability
An attacker can exploit this issue through readily available tools.
An attacker can exploit this issue through readily available tools.
References
Cogent Real-Time Systems DataHub CVE-2014-3788 Remote Heap Buffer Overflow Vulnerability
References:
References:
- Cogent DataHub HomePage (Cogent Real-Time Systems Inc)
- Version 7.3.5 - April 29, 2014 (Cogent Real-Time Systems)
- Cogent DataHub Heap Buffer Overflow Remote Code Execution Vulnerability (HP Zero day initiative)