vendor:
DAQMaster
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DAQMaster
Affected Version From: 1.5.2000
Affected Version To: 1.7.2003
Patch Exists: NO
Related CWE:
CPE: a:autonics_corporation:daqmaster:1.7.3
Platforms Tested: Windows 7 Professional SP1, Windows 7 Ultimate SP1
2015
Autonics DAQMaster 1.7.3 DQP Parsing Buffer Overflow Code Execution
The vulnerability is caused due to a boundary error in the processing of a project file, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .DQP project file with a large array of bytes inserted in the 'Description' element. Successful exploitation could allow execution of arbitrary code on the affected machine.
Mitigation:
Unknown