An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.
Weakness
The product does not release or incorrectly releases a resource before it is made available for re-use.
Affected Software
| Name |
Vendor |
Start Version |
End Version |
| Codemeter |
Wibu |
* |
7.10 (excluding) |
Potential Mitigations
- Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
- For example, languages such as Java, Ruby, and Lisp perform automatic garbage collection that releases memory for objects that have been deallocated.
References