We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2015-1007



Assignericscert
Reserved2015-01-10
Published2019-03-25
Updated2024-08-06

Description

A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC Display Professional versions prior to R9.4g, OptoOPCServer version R9.4c and prior that were installed by PAC Project installer, versions prior to R9.4008, and OptoDataLink version R9.4d and prior that were installed by PAC Project installer, versions prior to R9.4008. Opto 22 suggests upgrading to the new product version as soon as possible.

Problem types

Stack-based buffer overflow CWE-121

Product status

< R9.4008
affected

< R9.4008
affected

< R9.4g
affected

< R9.4g
affected

R9.4c and prior that were installed by PAC Project installer versions prior to R9.4008
affected

R9.4d and prior that were installed by PAC Project installer versions prior to R9.4008
affected

References

https://ics-cert.us-cert.gov/advisories/ICSA-15-120-01

cve.org CVE-2015-1007

nvd.nist.gov CVE-2015-1007

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.