Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
BID:101667
Info
Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 101667 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-12969 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2017 12:00AM |
| Updated: | Dec 19 2017 09:00PM |
| Credit: | John Page. |
| Vulnerable: |
Avaya IP Office Contact Center 9.1 Avaya IP Office Contact Center 10.1 Avaya IP Office Contact Center 10.0 |
| Not Vulnerable: |
Avaya IP Office Contact Center 10.1.1 |
Discussion
Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
Avaya IP Office Contact Center is prone to a remote buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the user. Failed attempts will likely cause a denial-of-service condition.
Avaya IP Office (IPO) versions 9.1.0 through 10.1 are vulnerable.
Avaya IP Office Contact Center is prone to a remote buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the user. Failed attempts will likely cause a denial-of-service condition.
Avaya IP Office (IPO) versions 9.1.0 through 10.1 are vulnerable.
Exploit / POC
Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Avaya IP Office Contact Center CVE-2017-12969 Remote Buffer Overflow Vulnerability
References:
References:
- Avaya Homepage (Avaya Inc.)
- CVE-2017-12969 Avaya OfficeScan IPO Remote ActiveX Buffer Overflow (Seclists.org)
- IP Office Contact Center Memory Corruption (Avaya)