Buffer overflow in GENESIS32 and BizViz - CVE-2011-5089

 

Buffer overflow in GENESIS32 and BizViz - CVE-2011-5089

Published: April 18, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44133
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2011-5089
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ICONICS, Inc.
Affected software:
GENESIS32
BizViz

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long password.


How to mitigate CVE-2011-5089

Install update from vendor's website.

Sources