PT-2017-14702 · Intel · Indeo Otter

Published

2017-12-01

·

Updated

2017-12-15

·

CVE-2017-17086

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Indeo Otter versions 1.7.4 and earlier
Description The issue concerns the mishandling of a "" substring in an initial DP payload, which can be exploited by remote attackers to cause a denial of service (crash) or possibly have other unspecified impacts. This has been demonstrated using the Plan Editor.
Recommendations For Indeo Otter versions 1.7.4 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17086

Affected Products

Indeo Otter