发布日期:2012-06-28 更新日期:2012-06-28受影响系统: General Electric Proficy HMI/SCADA-iFIX 5.1 General Electric Proficy HMI/SCADA-iFIX 5.0 General Electric Proficy Historian 4.5 General Electric Proficy Historian 4.0 General Electric Proficy Historian 3.5 General Electric Proficy Historian 3.1 描述: -------------------------------------------------------------------------------- BUGTRAQ ID: 54215 CVE(CAN) ID: CVE-2012-2515,CVE-2012-2516GE Proficy产品提供数据收集、过程自动化控制和自动化硬件产品和服务。多款GE Proficy产品在实现上存在远程栈缓冲区溢出和命令注入漏洞,攻击者可利用这些漏洞在使用ActiveX控件的应用中执行任意shell命令和代码。<*来源:Andrea Micalizzi *>建议: -------------------------------------------------------------------------------- 厂商补丁:General Electric ---------------- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:http://www.ge-ip.com/products/2420ComSndFTP服务器格式字符串漏洞HP OpenView Performance Manager远程代码执行漏洞相关资讯 缓冲区溢出漏洞