This application requires Javascript for optimal performance.

Smart.Software.Solution.CoDeSys.Gateway.Server.Integer.Overflow

Release Date

Dec 22, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an Integer Overflow vulnerability in Smart Software Solutions CoDeSys.

The vulnerability is due to a lack of validation of a user-supplied length value. Successful attacks may allow attackers to execute arbitrary code within the context of the service.

Affected Products

Smart Software Solutions CoDeSys 3.4 SP4 patch 2 and prior

Recommended Actions

Currently we are not aware of any vendor supplied patches.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-5008

Reference/s

https://portal.telussecuritylabs.com/threat/TSL20111202-08
http://www.securityfocus.com/bid/50849 (BugTraq)

Reference: VID-30611