CVE-2016-6448

A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:meeting_server:1.8.15:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.8_base:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 02:56

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/94076 - () http://www.securityfocus.com/bid/94076 -
References () http://www.securitytracker.com/id/1037181 - () http://www.securitytracker.com/id/1037181 -
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1 - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1 - Vendor Advisory

Information

Published : 2016-11-03 21:59

Updated : 2024-11-21 02:56


NVD link : CVE-2016-6448

Mitre link : CVE-2016-6448

CVE.ORG link : CVE-2016-6448


JSON object : View

Products Affected

cisco

  • meeting_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer