SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#596268

Wonderware SuiteLink null pointer dereference

Overview

A vulnerability in the way Wonderware SuiteLink handles malformed TCP packets could result in a denial of service.

I. Description

Wonderware SuiteLink is a protocol based on TCP/IP that runs as a service listening for connections on port 5413/tcp on Microsoft Windows operating systems. A vulnerability exists in the way the Wonderware SuiteLink Service slssvc.exe handles malformed TCP packets. According to Core Security Advisory CORE-2008-0129:

    Un-authenticated client programs connecting to the service can send a malformed packet that causes a memory allocation operation (a call to new() operator) to fail returning a NULL pointer. Due to a lack of error-checking for the result of the memory allocation operation, the program later tries to use the pointer as a destination for memory copy operation, triggering an access violation error and terminating the service.

Note that this issue affects Wonderware SuiteLink prior to version 2.0 Patch 01.

II. Impact

A remote, unauthenticated attacker may be able to cause a denial-of-service condition.

III. Solution

Apply an update

This issue is addressed in Wonderware SuiteLink Version 2.0 Patch 01. Wonderware SuiteLink customers should refer to Wonderware Tech Alert 106 and Wonderware Security Manual - Securing Industrial Control Systems for more details.

Systems Affected

VendorStatusDate Updated
Invensys Vulnerable23-May-2008
WonderwareVulnerable23-May-2008

References


http://www.coresecurity.com/?action=item&id=2187
http://www.securityfocus.com/bid/28974
http://secunia.com/advisories/30063/
http://www.wonderware.com/support/mmi/comprehensive/kbcd/html/t002260.htm
http://www.wonderware.com/support/web/secure/downloads/download_serve.asp?id=2355&url=http://www.wonderware.com/support/mmi/registered/patchfixes/SL2.0P1.zip
http://www.wonderware.com/support/mmi/esupport/securitycentral/documents/BestPractices/WWSecGd041707
http://portal.wonderware.com/sites/securitycentral/default.aspx

Credit

This vulnerability was reported in Core Security Advisory CORE-2008-0129.

This document was written by Chris Taschner.

Other Information

Date Public05/05/2008
Date First Published05/06/2008 04:01:06 PM
Date Last Updated05/23/2008
CERT Advisory 
CVE-ID(s)CVE-2008-2005
NVD-ID(s)CVE-2008-2005
US-CERT Technical Alerts 
Metric3.07
Document Revision13

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2008 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader