CVE-2011-10034: IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through attacker-controlled memory, resulting in denial-of-service. In some conditions, remote code execution may be possible.
Other sources
IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-10034?
CVE-2011-10034 is categorized as a critical vulnerability due to the risk of remote denial of service caused by the use-after-free condition.
How do I fix CVE-2011-10034?
To mitigate CVE-2011-10034, upgrade the IRAI AUTOMGEN software to version 8.0.0.8 or later.
What types of attacks can exploit CVE-2011-10034?
CVE-2011-10034 can be exploited to perform remote denial of service attacks by manipulating project files.
Who is affected by CVE-2011-10034?
Users of IRAI AUTOMGEN versions up to and including 8.0.0.7 are vulnerable to CVE-2011-10034.
What is the impact of CVE-2011-10034 on affected systems?
The impact of CVE-2011-10034 includes potential system crashes and service disruption due to the exploitation of the vulnerability.