Release date:
Updated on:
Affected Systems:
Winlog Pro 2.7
Unaffected system:
Winlog Pro 2.7.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45813
Cve id: CVE-2011-0517
Winlog Pro is a SCADA/HMI software package for managing industrial and civil factories.
Winlog Pro has a stack buffer overflow vulnerability when processing malformed packets. Remote attackers can exploit this vulnerability to execute arbitrary code, which may cause DOS.
<* Source: Luigi Auriemma (aluigi@pivx.com)
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.securityfocus.com/data/vulnerabilities/exploits/45813.zip
Http://www.securityfocus.com/data/vulnerabilities/exploits/45813.rb
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Winlog Pro
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sielcosistemi.com/en/products/winlog_scada_hmi/