The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/596268 | third party advisory us government resource |
http://www.coresecurity.com/?action=item&id=2187 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42221 | vdb entry |
http://www.securityfocus.com/bid/28974 | vdb entry |
https://www.exploit-db.com/exploits/6474 | exploit |
http://www.securitytracker.com/id?1019966 | vdb entry |
http://www.securityfocus.com/archive/1/491623/100/0/threaded | mailing list |
http://secunia.com/advisories/30063 | third party advisory |