Release date:
Updated on:
Affected Systems:
AVAYA Aura & #174; Application Server 2.0
AVAYA Aura & #174; Application Server 1.0
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-5096
Avaya is a vendor that provides IP communication and enterprise-oriented communication network design, construction, deployment and management. Aura & #174; Application Server provides secure and unified inter-media encrypted communication.
The cstore.exe Process monitored by Media Application serverhas a buffer overflow vulnerability. If a remote attacker can establish a connection to the listening process, attackers can execute arbitrary code with system-level permissions.
<* Source: AbdulAziz harsiri
Link: http://zerodayinitiative.com/advisories/ZDI-11-260/
Https://downloads.avaya.com/css/P8/documents/100146108
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
AVAYA
-----
AVAYA has released a Security Bulletin (ASA-2011-213) and patches for this:
ASA-2011-213: Media Application Server Remote Code Execution Vulnerability
Link: https://downloads.avaya.com/css/P8/documents/100146108