Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802469
Category:Buffer overflow
Title:Avaya WinPDM Multiple Buffer Overflow Vulnerabilities
Summary:Avaya WinPDM is prone to multiple buffer overflow vulnerabilities.
Description:Summary:
Avaya WinPDM is prone to multiple buffer overflow vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to a boundary error in,

- Unite Host Router service (UniteHostRouter.exe) when processing certain
requests can be exploited to cause a stack-based buffer overflow via
long string to the 'To:' field sent to UDP port 3217.

- UspCsi.exe when processing certain crafted overly long string requests
can be exploited to cause a heap-based buffer overflow via a specially
crafted overly long string sent to UDP port 10136.

- CuspSerialCsi.exe when processing certain crafted overly long string
requests can be exploited to cause a heap-based buffer overflow via a
specially crafted overly long string sent to UDP port 10158.

- MwpCsi.exe when processing certain crafted overly long string requests
can be exploited to cause a heap-based buffer overflow via a specially
crafted overly long string sent to UDP port 10137.

- PMServer.exe when processing certain requests can be exploited to cause
a heap-based buffer overflow via a specially crafted overly long string
sent to UDP port 10138.

Vulnerability Impact:
Successful exploitation will allow unauthenticated attackers to cause the
application to crash.

Affected Software/OS:
Avaya WinPDM version 3.8.2 and prior.

Solution:
Upgrade to Avaya WinPDM 3.8.5 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.