vendor:
MPQT/PACS
by:
bashis
7.5
CVSS
HIGH
Heap Overflow and Information Leakage
119
CWE
Product Name: MPQT/PACS
Affected Version From: MPQT series < v7.20.x/6.50.1.2, PACS series < v1.30.0.2/1.60.0/1.10.0.2/1.65.1
Affected Version To: MPQT series > v7.30/6.50.1.3 (Releases from September to November 2017), Not vulnerable (Releases from October to November 2017)
Patch Exists: YES
Related CWE:
CPE: a:axis_communications:mpqt
Platforms Tested:
2017
Axis Communications MPQT/PACS Heap Overflow and Information Leakage
The vulnerability allows remote attackers to cause a heap overflow and obtain information from affected devices. The vulnerability exists in the CGI_decode function in /usr/lib/libcgiparser.so, which handles URL decoding of '%xx'. By supplying a single '%', the function tries to decode [% + NULL + Next char], resulting in a longer string than expected. This can lead to information leakage and potential exploitation.
Mitigation:
The best way to find a fixed firmware is to check the Axis advisory and look for 'ACV-120444' in the release notes. Users are recommended to update to a non-vulnerable version of the MPQT or PACS series.