Overview
Medicomp's MEDCIN Engine provide electronic health records (EHR) tools and information to medical professionals. MEDCIN Engine versions before version 2.22.20153.226 are vulnerable to several buffer overflows.
Description
| Medicomp MEDCIN Engine prior to version 2.22.20153.226 is vulnerable to several buffer overflows and an out-of-bounds write. CWE-121: Stack-based Buffer Overflow - CVE-2015-2898, CVE-2015-2901 | 
Impact
| An unauthenticated remote attacker sending a specially crafted packet may be able to overwrite data in memory, cause the software to leak information to the attacker, and/or cause a denial of service. A remote attacker may also be able to execute code. | 
Solution
| Apply an update | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P | 
| Temporal | 5.8 | E:POC/RL:U/RC:UR | 
| Environmental | 5.0 | CDP:ND/TD:M/CR:H/IR:H/AR:ND | 
References
Acknowledgements
Thanks to Ryan Wincey for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2015-2898, CVE-2015-2899, CVE-2015-2900, CVE-2015-2901, CVE-2015-6006 | 
| Date Public: | 2015-10-20 | 
| Date First Published: | 2015-10-20 | 
| Date Last Updated: | 2015-10-20 15:33 UTC | 
| Document Revision: | 81 |