CVE-2012-3007 Information

Description

Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5 DASABCIP before 4.1 SP2 DASSiDirect before 3.0 DAServer Runtime Components before 3.0 SP2 and other products allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string.

Reference

http://secunia.com/advisories/49173 http://www.securityfocus.com/bid/53563 http://www.us-cert.gov/control_systems/pdf/ICSA-12-171-01.pdf

Share on: