An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch and 2016 before f2 Patch. A specially crafted VI file can cause a user controlled value to be used as a loop terminator resulting in internal heap corruption. An attacker controlled VI file can be used to trigger this vulnerability, exploitation could lead to remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2017-03-31T18:00:00
Updated: 2024-08-05T14:02:07.786Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2775
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-03-31T18:59:00.483
Modified: 2024-11-21T03:24:07.950
Link: CVE-2017-2775
Redhat
No data.