An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-26963 An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T08:39:25.924Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-29T16:15:14.887

Modified: 2024-11-21T05:34:37.870

Link: CVE-2020-5806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.