CVE ID | CVE-2015-4060 |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Wavelink |
AFFECTED PRODUCTS |
ConnectPro |
VULNERABILITY DETAILS |
The specific flaw exists in the parsing of HTTP requests in WLTermProxyService.exe listening by default on port 4428. When parsing large HTTP headers, the application will overflow a heap buffer due to an unsafe memory block copy operation. An attacker could leverage this to execute arbitrary code in the context of SYSTEM. |
ADDITIONAL DETAILS |
~2/20/2015 - ZDI called Wavelink customer service and a recorded message indicated these products are supported by another entity -- Mitigation:
|
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi (rgod) |