First published: Mon Oct 01 2018(Updated: )
Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fujielectric Alpha5 Smart Loader Firmware | <=3.7 | |
Fujielectric Alpha5 Smart Loader |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-14794 is critical.
Fuji Electric Alpha5 Smart Loader versions 3.7 and prior are affected by CVE-2018-14794.
CVE-2018-14794 allows an attacker to overflow a heap-based buffer by copying the entire contents of a project file without performing a length/size check.
No, versions of Fuji Electric Alpha5 Smart Loader after 3.7 are not affected by CVE-2018-14794.
No specific patch information is available for CVE-2018-14794. Please refer to the vendor's advisory or contact Fuji Electric for more information.