HIGH7.5
GHSA-782p-53wq-cxmj
High severity vulnerability that affects OPCFoundation.NetStandard.Opc.Ua
Quick fix
GHSA-782p-53wq-cxmj — OPCFoundation.NetStandard.Opc.Ua: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua --version 1.4.353.15Details
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua
Introduced in:
0Fixed in: 1.4.353.15Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua --version 1.4.353.15References
- https://nvd.nist.gov/vuln/detail/CVE-2018-12086[ADVISORY]
- https://github.com/advisories/GHSA-782p-53wq-cxmj[ADVISORY]
- https://opcfoundation-onlineapplications.org/faq/SecurityBulletins/OPC_Foundation_Security_Bulletin_CVE-2018-12086.pdf[WEB]
- https://www.debian.org/security/2018/dsa-4359[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html[WEB]
- http://www.securityfocus.com/bid/105538[WEB]
- http://www.securitytracker.com/id/1041909[WEB]