CVE-2012-3797
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
25/06/2012
Last modified:
11/04/2025
Description
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pro-face:pro-server_ex:*:*:*:*:*:*:*:* | 1.30.000 (including) | |
| cpe:2.3:a:pro-face:pro-server_ex:1.21.000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pro-face:pro-server_ex:1.23.000:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pro-face:pro-server_ex:1.24.200:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pro-face:wingp_pc_runtime:*:*:*:*:*:*:*:* | 3.1.00 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://aluigi.org/adv/proservrex_1-adv.txt
- http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01
- http://secunia.com/advisories/49172
- http://www.securityfocus.com/bid/53499
- https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt
- https://www.hmisource.com/otasuke/news/2012/0606.html
- http://aluigi.org/adv/proservrex_1-adv.txt
- http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01
- http://secunia.com/advisories/49172
- http://www.securityfocus.com/bid/53499
- https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt
- https://www.hmisource.com/otasuke/news/2012/0606.html



