CVE-2017-11309

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
Configurations

Configuration 1 (hide)

cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:07

Type Values Removed Values Added
References () http://downloads.avaya.com/css/P8/documents/101044086 - Vendor Advisory () http://downloads.avaya.com/css/P8/documents/101044086 - Vendor Advisory
References () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt - () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt -
References () http://packetstormsecurity.com/files/144883/Avaya-IP-Office-IPO-10.1-Soft-Console-Remote-Buffer-Overflow.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/144883/Avaya-IP-Office-IPO-10.1-Soft-Console-Remote-Buffer-Overflow.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/101674 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101674 - Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/43121/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/43121/ - Exploit, Third Party Advisory, VDB Entry

07 Nov 2023, 02:38

Type Values Removed Values Added
References
  • {'url': 'http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt', 'name': 'http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt -

Information

Published : 2017-11-10 02:29

Updated : 2024-11-21 03:07


NVD link : CVE-2017-11309

Mitre link : CVE-2017-11309

CVE.ORG link : CVE-2017-11309


JSON object : View

Products Affected

avaya

  • ip_office
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer