#VU20900 Out-of-bounds read in Crimson - CVE-2019-10978
Published: September 6, 2019 / Updated: September 6, 2019
Crimson
Red Lion Controls
Description
The vulnerability allows a remote attacker to disclose sensitive information on the target system.
The vulnerability exists due to a boundary error when processing CD31 files. A remote attacker can trick a victim to open a specially crafted file, trigger out-of-bounds read error and disclose sensitive information.
Remediation
External links
- https://ics-cert.us-cert.gov/advisories/icsa-19-248-01
- https://www.zerodayinitiative.com/advisories/ZDI-19-796/
- https://www.zerodayinitiative.com/advisories/ZDI-19-795/
- https://www.zerodayinitiative.com/advisories/ZDI-19-790/
- https://www.zerodayinitiative.com/advisories/ZDI-19-794/
- https://www.zerodayinitiative.com/advisories/ZDI-19-792/