USG series and NGFW Module Buffer Overflow Vulnerability (CVE-2016-4577)
USG series and NGFW Module Buffer Overflow Vulnerability (CVE-2016-4577)
Release date:
Updated on:
Affected Systems:
NGFW Module V500R001C00
USG USG6600
USG USG6500
USG USG6300
Unaffected system:
NGFW Module V500R001C00
Description:
CVE (CAN) ID: CVE-2016-4577
is a provider of information and communication solutions in China.
Multiple products have the buffer overflow vulnerability in the implementation of Smart DNS. By constructing data packets, remote attackers can cause DoS attacks or execute arbitrary code.
<* Source:
Link: http://www.huawei.com/en/psirt/security-advisories/sa-20160511-01-dns-en
*>
Suggestion:
Vendor patch:
------
has released a Security Bulletin (-sa-20160511-01-dns-en) and patches for this:
sa-20160511-01-dns-en: Buffer Overflow Vulnerability in Several Products
Link: http://www.huawei.com/en/psirt/security-advisories/sa-20160511-01-dns-en
This article permanently updates the link address: