Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
BID:61913
Info
Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
| Bugtraq ID: | 61913 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-3462 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2013 12:00AM |
| Updated: | Aug 21 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Communications Manager 8.6(2a)su1 Cisco Unified Communications Manager 8.6 Cisco Unified Communications Manager 8.5(1)SU2 Cisco Unified Communications Manager 8.5(1)SU1 Cisco Unified Communications Manager 8.5(1) Cisco Unified Communications Manager 8.5 Cisco Unified Communications Manager 8.0(1) Cisco Unified Communications Manager 7.1(5b)su5 Cisco Unified Communications Manager 7.1(5b)SU4 Cisco Unified Communications Manager 7.1(5b)su3 Cisco Unified Communications Manager 7.1(5b)SU2 Cisco Unified Communications Manager 7.1(5B) Cisco Unified Communications Manager 7.1(5A) Cisco Unified Communications Manager 7.1(5)Su1a Cisco Unified Communications Manager 7.1(5)Su1 Cisco Unified Communications Manager 7.1(5) Cisco Unified Communications Manager 7.1(3b)su2 Cisco Unified Communications Manager 7.1(3b)su1 Cisco Unified Communications Manager 7.1(3B) Cisco Unified Communications Manager 7.1(3A)Su1a Cisco Unified Communications Manager 7.1(3a)su1 Cisco Unified Communications Manager 7.1(3A) Cisco Unified Communications Manager 7.1(3) Cisco Unified Communications Manager 7.1(2B)Su1 Cisco Unified Communications Manager 7.1(2B) Cisco Unified Communications Manager 7.1(2a)su1 Cisco Unified Communications Manager 7.1(2A) Cisco Unified Communications Manager 7.1(2) Cisco Unified Communications Manager 7.1 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
Cisco Unified Communications Manager is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
This issue is being tracked by Cisco Bug ID CSCud54358.
Cisco Unified Communications Manager is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
This issue is being tracked by Cisco Bug ID CSCud54358.
Exploit / POC
Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Unified Communications Manager CVE-2013-3462 Buffer Overflow Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Unified Communications Manager (CallManager) (Cisco)