1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Avaya AES LibTIFF LZW Decoder Buffer Underflow Vulnerability

Report ID: SA32136
Source: Secunia
Date of Discovery: 09.10.2008
Criticality: Moderate
Affects:
Avaya Application Enablement Services 3.x

Compromise From: From remote
Compromise Type: System access
DoS

Summary

Avaya has acknowledged a vulnerability in Avaya Application Enablement Services (AES), which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Detailed Description

Avaya has acknowledged a vulnerability in Avaya Application Enablement Services (AES), which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

The vulnerability is reported in version 3.1.6.

Solution

The vendor recommends that local and network access to the affected systems be restricted until an update is available.

CVE Reference

CVE-2008-2327