Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
BID:47947
Info
Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 47947 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2011 12:00AM |
| Updated: | Oct 09 2012 09:40AM |
| Credit: | Abdul-Aziz Hariri |
| Vulnerable: |
Avaya AvayaWinPDM 3.8.2 |
| Not Vulnerable: |
Avaya AvayaWinPDM 3.8.5 |
Discussion
Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
AvayaWinPDM is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Successful exploits may allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
AvayaWinPDM versions prior to 3.8.5 are vulnerable.
AvayaWinPDM is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Successful exploits may allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
AvayaWinPDM versions prior to 3.8.5 are vulnerable.
Exploit / POC
Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
A commercial exploit is available through VUPEN Security - Exploit and PoCs service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
A commercial exploit is available through VUPEN Security - Exploit and PoCs service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
References:
References:
- Avaya Homepage (Avaya Inc.)
- AvayaWinPDM Homepage (Avaya Inc.)
- ASA-2011-143- Avaya Security Advisory (Avaya Inc.)