PT-2013-2022 · Huawei · Huawei Utps

Dark-Puzzle

+1

·

Published

2013-06-20

·

Updated

2013-06-21

·

CVE-2012-6568

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei UTPS version 1.0
Description A buffer overflow issue exists in the back-end component due to a long IDS PLUGIN NAME string in a plug-in configuration file, allowing local users to gain privileges.
Recommendations For Huawei UTPS version 1.0, consider restricting access to the plug-in configuration file to prevent exploitation of the buffer overflow issue until a fix is available. As a temporary workaround, limit the length of the IDS PLUGIN NAME string in the plug-in configuration file to prevent buffer overflow.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6568

Affected Products

Huawei Utps