Schwachstellenklasse
S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service
Quellen
- https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_ack_bs.c
- https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_bs.c
- https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/Common/opcua_types/sopc_encoder.c
- https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/tests/ClientServer/CMakeLists.txt
- https://gitlab.com/systerel/S2OPC/-/work_items/1785
- https://gitlab.com/systerel/S2OPC/-/work_items/1785
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.