CVE-2017-12969

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:avaya:ip_office_contact_center:9.1:sp11:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.0.2209.1540:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.6:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.7:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.8:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:9.1.9:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:10.0:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:10.0.0.3-8600.1705:*:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office_contact_center:10.1:*:*:*:*:*:*:*

History

21 Nov 2024, 03:10

Type Values Removed Values Added
References () http://downloads.avaya.com/css/P8/documents/101044091 - Vendor Advisory () http://downloads.avaya.com/css/P8/documents/101044091 - Vendor Advisory
References () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt - () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt -
References () http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2017/Nov/17 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Nov/17 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/101667 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101667 - Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/43120/ - Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/43120/ - Third Party Advisory, VDB Entry

07 Nov 2023, 02:38

Type Values Removed Values Added
References
  • {'url': 'http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt', 'name': 'http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt', 'tags': [], 'refsource': 'MISC'}
  • () http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt -

Information

Published : 2017-11-10 02:29

Updated : 2024-11-21 03:10


NVD link : CVE-2017-12969

Mitre link : CVE-2017-12969

CVE.ORG link : CVE-2017-12969


JSON object : View

Products Affected

avaya

  • ip_office_contact_center
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer