CVE-2012-3008: Buffer Overflow
Published Jul 20, 2012
·Updated
Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items.
Affected Software
2 affected components
OSIsoft PI OPC DA Interface<=2.3.17.18
OSIsoft PI OPC DA Interface=2.3.16.16
Event History
Jul 20, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3008?
CVE-2012-3008 is considered to have a critical severity due to its potential for remote code execution.
2
How do I fix CVE-2012-3008?
To fix CVE-2012-3008, update OSIsoft PI OPC DA Interface to version 2.3.20.9 or later.
3
Who is affected by CVE-2012-3008?
CVE-2012-3008 affects users of OSIsoft PI OPC DA Interface versions prior to 2.3.20.9.
4
What are the potential impacts of CVE-2012-3008?
The potential impacts of CVE-2012-3008 include unauthorized remote code execution by attackers.
5
How does the buffer overflow in CVE-2012-3008 occur?
The buffer overflow in CVE-2012-3008 occurs when an attacker sends specially crafted packet data during message processing.