Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g7c-253j-whp9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

EPSS

Процентиль: 0%
0.00005
Низкий

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.5
nvd
около 5 лет назад

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

CVSS3: 5.5
fstec
около 5 лет назад

Уязвимость функции CServerManager::HandleBrowseLoadIconStreamRequest программного обеспечения системы автоматизации FactoryTalk Linx, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00005
Низкий

Дефекты

CWE-770