2012-08-19 22:55:01 2012-08-20 06:00:00

Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet with a crafted positive integer after the opcode.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

COMPLETE

Integrity

COMPLETE

Availability

COMPLETE
Martin Pitt jockey 0.9.7-0ubuntu7.4 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.5 Martin Pitt jockey 0.9.7-0ubuntu7.7 Martin Pitt jockey 0.9.7-0ubuntu7.8 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.1 Martin Pitt jockey 0.9.7-0ubuntu7.9 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Beta 2 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Release Candidate 1 MartiniCreations PassmanLite Password Manager 1.42 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Beta 1 Martin Pitt jockey 0.9.7-0ubuntu7.5 Martin Nagy bind-dyndb-ldap 0.1.0a1 MartiniCreations PassmanLite Password Manager 1.43 Martin Nagy bind-dyndb-ldap 0.1.0b marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 Beta 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.6 Sielcosistemi Winlog lite 2.07.16 (not an official CPE) Martin Pitt jockey 0.9.7-0ubuntu7.2 Martin Lee Multi-lingual E-Commerce System 0.2 MartiniCreations PassmanLite Password Manager 1.44 Martin Pitt jockey 0.9.7-0ubuntu7.6 Sielcosistemi Winlog pro 2.07.16 (not an official CPE) Martin Nagy bind-dyndb-ldap 0.2.0 Martin Nagy bind-dyndb-ldap 1.0.0b1 Martin Pitt jockey 0.9.7-0ubuntu7.11 MartiniCreations PassmanLite Password Manager 1.49 MartiniCreations PassmanLite Password Manager 1.48 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 Alpha 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.2 Martin Nagy bind-dyndb-ldap 1.1.0b1 MartiniCreations PassmanLite Password Manager 1.47 Martin Nagy bind-dyndb-ldap 1.1.0a2 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.3 Martin Nagy bind-dyndb-ldap 1.1.0a1 Martin Nagy bind-dyndb-ldap 1.0.0 release candidate 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.x-dev marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.8 MartiniCreations PassmanLite Password Manager 1.46 Martin Nagy bind-dyndb-ldap 1.1.0b2 MartiniCreations PassmanLite Password Manager 1.45 Martin Pitt jockey 0.9.7-0ubuntu7.3 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.4 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.7 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Martin Pitt jockey 0.9.7-0ubuntu7.1 Martin Pitt jockey 0.9.7-0ubuntu7 Martin Nagy bind-dyndb-ldap 1.1.0 release candidate 1 MartiniCreations PassmanLite Password Manager 1.50 Marvell Mrvlusgtracking 1.0.0 Marvell Mrvlusgtracking 1.0.7 Martin Pitt jockey 0.9.7-0ubuntu7.10 Marvell Mrvlusgtracking 1.0.1

Improper Input Validation (ID 20)

Related CAPEC 58 Buffer Overflow via Environment Variables (CAPEC-ID 10) Server Side Include (SSI) Injection (CAPEC-ID 101) Cross Zone Scripting (CAPEC-ID 104) Cross Site Scripting through Log Files (CAPEC-ID 106) Command Line Execution through SQL Injection (CAPEC-ID 108) Object Relational Mapping Injection (CAPEC-ID 109) SQL Injection through SOAP Parameter Tampering (CAPEC-ID 110) Subverting Environment Variable Values (CAPEC-ID 13) Format String Injection (CAPEC-ID 135) LDAP Injection (CAPEC-ID 136) Relative Path Traversal (CAPEC-ID 139) Client-side Injection-induced Buffer Overflow (CAPEC-ID 14) Variable Manipulation (CAPEC-ID 171) Embedding Scripts in Non-Script Elements (CAPEC-ID 18) Flash Injection (CAPEC-ID 182) Cross-Site Scripting Using Alternate Syntax (CAPEC-ID 199) Exploiting Trust in Client (aka Make the Client Invisible) (CAPEC-ID 22) XML Nested Payloads (CAPEC-ID 230) XML Oversized Payloads (CAPEC-ID 231) Filter Failure through Buffer Overflow (CAPEC-ID 24) Cross-Site Scripting via Encoded URI Schemes (CAPEC-ID 244) XML Injection (CAPEC-ID 250) Environment Variable Manipulation (CAPEC-ID 264) Global variable manipulation (CAPEC-ID 265) Leverage Alternate Encoding (CAPEC-ID 267) Fuzzing (CAPEC-ID 28) Using Leading 'Ghost' Character Sequences to Bypass Input Filters (CAPEC-ID 3) Accessing/Intercepting/Modifying HTTP Cookies (CAPEC-ID 31) Embedding Scripts in HTTP Query Strings (CAPEC-ID 32) MIME Conversion (CAPEC-ID 42) Exploiting Multiple Input Interpretation Layers (CAPEC-ID 43) Buffer Overflow via Symbolic Links (CAPEC-ID 45) Overflow Variables and Tags (CAPEC-ID 46) Buffer Overflow via Parameter Expansion (CAPEC-ID 47) Signature Spoof (CAPEC-ID 473) XML Client-Side Attack (CAPEC-ID 484) Embedding NULL Bytes (CAPEC-ID 52) Postfix, Null Terminate, and Backslash (CAPEC-ID 53) Simple Script Injection (CAPEC-ID 63) Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64) SQL Injection (CAPEC-ID 66) String Format Overflow in syslog() (CAPEC-ID 67) Blind SQL Injection (CAPEC-ID 7) Using Unicode Encoding to Bypass Validation Logic (CAPEC-ID 71) URL Encoding (CAPEC-ID 72) User-Controlled Filename (CAPEC-ID 73) Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78) Using Slashes in Alternate Encoding (CAPEC-ID 79) Buffer Overflow in an API Call (CAPEC-ID 8) Using UTF-8 Encoding to Bypass Validation Logic (CAPEC-ID 80) Web Logs Tampering (CAPEC-ID 81) XPath Injection (CAPEC-ID 83) AJAX Fingerprinting (CAPEC-ID 85) Embedding Script (XSS) in HTTP Headers (CAPEC-ID 86) OS Command Injection (CAPEC-ID 88) Buffer Overflow in Local Command-Line Utilities (CAPEC-ID 9) XSS in IMG Tags (CAPEC-ID 91) XML Parser Attack (CAPEC-ID 99)