Release date: 2011-11-28
Updated on: 2011-11-30
Affected Systems:
Steema Software TeeChart
Schneider Electric CitectHistorian 4.x
Schneider Electric CitectSCADA Reports 4.10
Schneider Electric Vijeo Historian 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50837
CVE (CAN) ID: CVE-2011-4034
TeeChart Pro ActiveX is a chart control developed by Steema SL in Spain. It is mainly used to generate various complex charts.
The TeeChart ActiveX control has a buffer overflow vulnerability. Attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Kuang-Chun Hung
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
Http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.google.com.hk/aclk? Sa = L & ai = ctba_zisntuedd1_mqwk7shmd8pxj4wck_yujccj9p1_caaqavdngywp -____