Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
BID:71409
Info
Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 71409 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-8001 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2014 12:00AM |
| Updated: | Dec 05 2014 01:56AM |
| Credit: | Oksana |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
The Cisco OpenH264 is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user supplied input.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
Cisco OpenH264 1.0.0, 1.1.1, and 1.2.2 are vulnerable.
The Cisco OpenH264 is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user supplied input.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
Cisco OpenH264 1.0.0, 1.1.1, and 1.2.2 are vulnerable.
Exploit / POC
Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco OpenH264 Media Processing Multiple Buffer Overflow Vulnerabilities
References:
References:
- Cisco Homepage (Cisco )