SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#711420

LiveData Server fails to properly handle Connection-Oriented Transport Protocol packets

Overview

The LiveData Server fails to handle malformed Connection-Oriented Transport Protocol (COTP) packets. This vulnerability may allow a remote attacker to crash the LiveData Server.

I. Description

The LiveData Server records and transmits data between two or more control systems. The Connection-Oriented Transport Protocol (COTP) is a transport layer protocol used in OSI networks. COTP is defined in ISO 8073. The LiveData implementation of COTP contains an unspecified vulnerability. By sending a specially crafted packet to a vulnerable LiveData Server, a remote attacker may be able to trigger this vulnerability.

II. Impact

A remote attacker can cause the LiveData Server to terminate abnormally, resulting in a denial-of-service condition.

III. Solution

Upgrade

This vulnerability is remedied in releases 5.00.62 or later of the LiveData Server products. This update is available on the LiveData web site.
 

Systems Affected

VendorStatusDate Updated
LiveData Inc.Vulnerable1-May-2007

References


http://www.livedata.com
http://secunia.com/advisories/25113/

Credit

This vulnerability was reported by Matt Franz of Digital Bond.

This document was written by Jeff Gennari.

Other Information

Date Public05/02/2007
Date First Published05/02/2007 02:35:37 PM
Date Last Updated07/20/2007
CERT Advisory 
CVE NameCVE-2007-2490
US-CERT Technical Alerts 
Metric1.21
Document Revision23

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader