Polycom HDX Series 'H.323' Format String Vulnerability
BID:58525
Info
Polycom HDX Series 'H.323' Format String Vulnerability
| Bugtraq ID: | 58525 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2013 12:00AM |
| Updated: | Mar 15 2013 12:00AM |
| Credit: | Moritz Jodeit of n.runs AG |
| Vulnerable: |
Polycom HDX 9000 0 Polycom HDX 8000 0 Polycom HDX 7000 0 Polycom HDX 6000 0 Polycom HDX 4000 0 |
| Not Vulnerable: |
Polycom HDX 9000 3.1.1 2 Polycom HDX 8000 3.1.1 2 Polycom HDX 7000 3.1.1 2 Polycom HDX 6000 3.1.1 2 Polycom HDX 4000 3.1.1 2 |
Discussion
Polycom HDX Series 'H.323' Format String Vulnerability
Polycom HDX Series devices are prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
An attacker may exploit this issue to execute arbitrary code with root access in the context of the vulnerable device. Failed exploit attempts will likely result in a denial-of-service condition.
Polycom HDX Series devices are prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
An attacker may exploit this issue to execute arbitrary code with root access in the context of the vulnerable device. Failed exploit attempts will likely result in a denial-of-service condition.