When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-094-01 | Mitigation Third Party Advisory US Government Resource |
https://www.zerodayinitiative.com/advisories/ZDI-19-344/ | |
https://ics-cert.us-cert.gov/advisories/ICSA-19-094-01 | Mitigation Third Party Advisory US Government Resource |
https://www.zerodayinitiative.com/advisories/ZDI-19-344/ |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://ics-cert.us-cert.gov/advisories/ICSA-19-094-01 - Mitigation, Third Party Advisory, US Government Resource | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-19-344/ - |
Information
Published : 2019-04-10 20:29
Updated : 2024-11-21 04:46
NVD link : CVE-2019-6556
Mitre link : CVE-2019-6556
CVE.ORG link : CVE-2019-6556
JSON object : View
Products Affected
omron
- common_components
- cx-programmer
CWE
CWE-416
Use After Free