Release date: 2011-12-21
Updated on: 2011-12-22
Affected Systems:
Wellintech KingView 65.30.2010.18018
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51159
Cve id: CVE-2011-4536
WellinTech is an automation control software development company in China. KingView is a Windows-based control, monitoring, and data collection application.
KingView has a heap buffer overflow vulnerability in implementation. by sending specially crafted packets that exceed a certain length and contain executable code to port 777/TCP, attackers can exploit this vulnerability to cause service crash and execute arbitrary code.
<* Source: Luigi Auriemma (aluigi@pivx.com)
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-11-355-02.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wellintech
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kingview.com/products/detail.aspx? Contentid = 24