First published: Mon Apr 13 2020(Updated: )
Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fujielectric V-server | <4.0.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10646 is a vulnerability in Fuji Electric V-Server Lite versions prior to 4.0.9.0 that allows for a heap-based buffer overflow.
CVE-2020-10646 has a severity score of 7.8 (high).
CVE-2020-10646 affects Fuji Electric V-Server Lite versions prior to 4.0.9.0 by causing a heap-based buffer overflow when parsing VPR files.
A heap-based buffer overflow is a vulnerability where a program writes more data to a buffer in the heap memory than it can handle, leading to memory corruption and potentially arbitrary code execution.
To fix CVE-2020-10646, you should update Fuji Electric V-Server Lite to version 4.0.9.0 or later.