OSIsoft pi opc da Interface Remote Stack Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
Osisoft pi opc da Interface <2.3.20.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54609
Cve id: CVE-2012-3008
Pi opc da Interface can be used to transmit data in the OPC server and PI system.
Versions earlier than OSIsoft pi opc da Interface 2.3.20.9 did not correctly verify that the OPC input message was executed for other processing. The stack buffer overflow vulnerability exists in the implementation, by sending message data when processing messages associated with the OPC project, you can allow remote authenticated users to release the memory address, resulting in a crash or arbitrary code execution in the affected applications.
<* Source: OSIsoft
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Osisoft
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://techsupport.osisoft.com/Products/