PT-2016-5795 · Meinberg · Meinberg Lantime M300+10

Ryan Wincey

·

Publicado

2016-07-03

·

Atualizado

2016-07-08

·

CVE-2016-3988

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Meinberg IMS-LANTIME M3000 versions prior to 6.20.004 Meinberg IMS-LANTIME M1000 versions prior to 6.20.004 Meinberg IMS-LANTIME M500 versions prior to 6.20.004 Meinberg LANTIME M900 versions prior to 6.20.004 Meinberg LANTIME M600 versions prior to 6.20.004 Meinberg LANTIME M400 versions prior to 6.20.004 Meinberg LANTIME M300 versions prior to 6.20.004 Meinberg LANTIME M200 versions prior to 6.20.004 Meinberg LANTIME M100 versions prior to 6.20.004 Meinberg SyncFire 1100 versions prior to 6.20.004 Meinberg LCES versions prior to 6.20.004
Description The issue is related to multiple stack-based buffer overflows in the NTP time-server interface. This allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a "POST" request.
Recommendations For Meinberg IMS-LANTIME M3000 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg IMS-LANTIME M1000 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg IMS-LANTIME M500 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M900 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M600 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M400 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M300 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M200 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LANTIME M100 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg SyncFire 1100 versions prior to 6.20.004, update the firmware to version 6.20.004 or later. For Meinberg LCES versions prior to 6.20.004, update the firmware to version 6.20.004 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3988

Produtos afetados

Meinberg Ims-Lantime M1000
Meinberg Ims-Lantime M3000
Meinberg Ims-Lantime M500
Meinberg Lantime M100
Meinberg Lantime M200
Meinberg Lantime M300
Meinberg Lantime M400
Meinberg Lantime M600
Meinberg Lantime M900
Meinberg Lces
Meinberg Syncfire 1100