Overview
Medicomp's MEDCIN Engine provide electronic health records (EHR) tools and information to medical professionals. MEDCIN Engine versions before version 2.22.20153.226 are vulnerable to several buffer overflows.
Description
Medicomp MEDCIN Engine prior to version 2.22.20153.226 is vulnerable to several buffer overflows and an out-of-bounds write. CWE-121: Stack-based Buffer Overflow - CVE-2015-2898, CVE-2015-2901 |
Impact
An unauthenticated remote attacker sending a specially crafted packet may be able to overwrite data in memory, cause the software to leak information to the attacker, and/or cause a denial of service. A remote attacker may also be able to execute code. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.8 | E:POC/RL:U/RC:UR |
Environmental | 5.0 | CDP:ND/TD:M/CR:H/IR:H/AR:ND |
References
Acknowledgements
Thanks to Ryan Wincey for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2015-2898, CVE-2015-2899, CVE-2015-2900, CVE-2015-2901, CVE-2015-6006 |
Date Public: | 2015-10-20 |
Date First Published: | 2015-10-20 |
Date Last Updated: | 2015-10-20 15:33 UTC |
Document Revision: | 81 |