CVE-2012-0257: Buffer Overflow
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0257?
CVE-2012-0257 is rated as high severity due to the risk of remote code execution through a heap-based buffer overflow.
How do I fix CVE-2012-0257?
To fix CVE-2012-0257, update to the latest version of the affected software as recommended by the vendor.
Which software is affected by CVE-2012-0257?
CVE-2012-0257 affects various Invensys software, including Wonderware Application Server 2012 and earlier, amongst others.
What are the potential impacts of CVE-2012-0257?
The potential impacts of CVE-2012-0257 include unauthorized access and execution of arbitrary code on affected systems.
Is there a workaround for CVE-2012-0257?
There are no known effective workarounds for CVE-2012-0257; upgrading the software is recommended for mitigation.