ID

VAR-E-201110-0215


TITLE

IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities

Trust: 0.3

sources: BID: 50045

DESCRIPTION

IRAI AUTOMGEN is prone to multiple remote code-execution vulnerabilities because it fails to properly validate user-supplied input.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploits can trigger a denial-of-service condition.
AUTOMGEN 8.0.0.7 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 50045

AFFECTED PRODUCTS

vendor:iraimodel:automgenscope:eqversion:8.0.0.7

Trust: 0.3

sources: BID: 50045

EXPLOIT

The following proof of concept is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/50045.zip">/data/vulnerabilities/exploits/50045.zip</a></li>

Trust: 0.3

sources: BID: 50045

PRICE

Free

Trust: 0.3

sources: BID: 50045

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 50045

CREDITS

Luigi Auriemma

Trust: 0.3

sources: BID: 50045

EXTERNAL IDS

db:BIDid:50045

Trust: 0.3

sources: BID: 50045

REFERENCES

url:http://www.irai.com/a8e/

Trust: 0.3

sources: BID: 50045

SOURCES

db:BIDid:50045

LAST UPDATE DATE

2022-07-27T09:43:05.069000+00:00


SOURCES UPDATE DATE

db:BIDid:50045date:2011-10-10T00:00:00

SOURCES RELEASE DATE

db:BIDid:50045date:2011-10-10T00:00:00