CVE-2018-8839: Buffer Overflow
Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code execution or cause the application to crash. CVSS v3 base score: 7.1; CVSS vector string: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics PMSoftto a version that resolves this vulnerability.Fixed in 2.11
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8839?
CVE-2018-8839 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2018-8839?
To mitigate CVE-2018-8839, upgrade Delta PMSoft to version 2.11 or later.
What types of vulnerabilities are associated with CVE-2018-8839?
CVE-2018-8839 is associated with multiple stack-based buffer overflow vulnerabilities.
What software versions are affected by CVE-2018-8839?
CVE-2018-8839 affects Delta PMSoft versions 2.10 and earlier.
Can CVE-2018-8839 be exploited remotely?
Yes, CVE-2018-8839 can be exploited by sending a specially crafted .ppm file to the affected application.