A10 Networks ACOS Remote Buffer Overflow Vulnerability
BID:66588
Info
A10 Networks ACOS Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 66588 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3976 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2014 12:00AM |
| Updated: | Jun 25 2014 06:46PM |
| Credit: | Francesco Perna |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
A10 Networks ACOS Remote Buffer Overflow Vulnerability
A10 Networks ACOS is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the application. Failed attacks may cause a denial-of-service condition.
ACOS 2.7.0-P2(build: 53) is vulnerable; other versions may also be affected.
A10 Networks ACOS is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the application. Failed attacks may cause a denial-of-service condition.
ACOS 2.7.0-P2(build: 53) is vulnerable; other versions may also be affected.
Exploit / POC
A10 Networks ACOS Remote Buffer Overflow Vulnerability
The researcher who found the issues has created proof-of-concept files. Please see the references for information.
The researcher who found the issues has created proof-of-concept files. Please see the references for information.
Solution / Fix
A10 Networks ACOS Remote Buffer Overflow Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
A10 Networks ACOS Remote Buffer Overflow Vulnerability
References:
References: