Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.802469
Categoría:Buffer overflow
Título:Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
Resumen:Avaya WinPDM is prone to multiple buffer overflow vulnerabilities.
Descripción:Summary:
Avaya WinPDM is prone to multiple buffer overflow vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to a boundary error in,

- Unite Host Router service (UniteHostRouter.exe) when processing certain
requests can be exploited to cause a stack-based buffer overflow via
long string to the 'To:' field sent to UDP port 3217.

- UspCsi.exe when processing certain crafted overly long string requests
can be exploited to cause a heap-based buffer overflow via a specially
crafted overly long string sent to UDP port 10136.

- CuspSerialCsi.exe when processing certain crafted overly long string
requests can be exploited to cause a heap-based buffer overflow via a
specially crafted overly long string sent to UDP port 10158.

- MwpCsi.exe when processing certain crafted overly long string requests
can be exploited to cause a heap-based buffer overflow via a specially
crafted overly long string sent to UDP port 10137.

- PMServer.exe when processing certain requests can be exploited to cause
a heap-based buffer overflow via a specially crafted overly long string
sent to UDP port 10138.

Vulnerability Impact:
Successful exploitation will allow unauthenticated attackers to cause the
application to crash.

Affected Software/OS:
Avaya WinPDM version 3.8.2 and prior.

Solution:
Upgrade to Avaya WinPDM 3.8.5 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

CopyrightCopyright (C) 2012 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.