Описание
Heap-based buffer overflow in LiveData Protocol Server 5.00.045, and other versions before update 500062 (5.00.062), allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file that causes a negative length to be used in a strncpy call.
Ссылки
- Vendor Advisory
- US Government Resource
- Patch
- Vendor Advisory
- US Government Resource
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 5.00.045 (включая)
cpe:2.3:a:livedata:protocol_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.20434
Средний
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Heap-based buffer overflow in LiveData Protocol Server 5.00.045, and other versions before update 500062 (5.00.062), allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file that causes a negative length to be used in a strncpy call.
EPSS
Процентиль: 95%
0.20434
Средний
10 Critical
CVSS2
Дефекты
NVD-CWE-Other