Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
BID:70211
Info
Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 70211 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-5501 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2014 12:00AM |
| Updated: | Sep 15 2014 12:00AM |
| Credit: | agix |
| Vulnerable: |
Sophos CyberoamOS 10.6.1 RC-4 Sophos CyberoamOS 10.4 GA |
| Not Vulnerable: |
Sophos CyberoamOS 10.6.1 GA |
Discussion
Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
Sophos Cyberoam is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can exploit these issues to execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.
The following versions are vulnerable:
Sophos CyberoamOS 10.4 GA and prior
Sophos CyberoamOS 10.6.1 RC-4 and prior
Sophos Cyberoam is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can exploit these issues to execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.
The following versions are vulnerable:
Sophos CyberoamOS 10.4 GA and prior
Sophos CyberoamOS 10.6.1 RC-4 and prior
Exploit / POC
Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sophos Cyberoam CVE-2014-5501 Stack Based Buffer Overflow Vulnerability
References:
References: