CVE ID | CVE-2015-4059 |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Wavelink |
AFFECTED PRODUCTS |
Terminal Emulation |
VULNERABILITY DETAILS |
The specific flaw exists in the parsing of HTTP requests in LicenseServer.exe listening by default on port 4420. When parsing large HTTP headers, the application will overflow a heap buffer due to an unsafe memory block copy operation. An attacker could leverage this to execute arbitrary code in the context of SYSTEM. |
ADDITIONAL DETAILS |
~2/20/2015 - ZDI called Wavelink customer service and a recorded message indicated these products are supported by another entity -- Mitigation: -- Vendor Patch: Here is a link: http://www.wavelink.com/Download-Emulation-License-Server-Software/
|
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi (rgod) |