PT-2013-1382 · Editran · Editran Communications Platform
Published
2013-06-28
·
Updated
2013-07-01
·
CVE-2010-5288
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EDItran Communications Platform version 4.1 R7
Description
The issue is related to a buffer overflow in the
lsConnectionCached function in editcp, which can be triggered by remote attackers sending a crafted packet to TCP port 7777. This can cause a denial of service, resulting in a daemon crash, or potentially allow the execution of arbitrary code.Recommendations
For EDItran Communications Platform version 4.1 R7, consider restricting access to TCP port 7777 until a patch is available. As a temporary workaround, disabling the
lsConnectionCached function in editcp may help mitigate the risk of exploitation.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Editran Communications Platform