CVE-2011-5008: Buffer Overflow
Published Dec 25, 2011
·Updated
Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.
Affected Software
1 affected component
3ssoftware Codesys=3.4-sp4
Event History
Dec 25, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5008?
CVE-2011-5008 has been classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2011-5008?
To mitigate CVE-2011-5008, update to a patched version of CoDeSys beyond 3.4 SP4 Patch 2 as provided by the vendor.
3
What systems are affected by CVE-2011-5008?
CVE-2011-5008 affects gateways utilizing CoDeSys version 3.4 SP4 Patch 2.
4
Can CVE-2011-5008 be exploited remotely?
Yes, CVE-2011-5008 can be exploited remotely if the vulnerable service is exposed to the internet.
5
What type of vulnerability is CVE-2011-5008?
CVE-2011-5008 is identified as an integer overflow vulnerability that leads to a heap-based buffer overflow.