First published: Fri Sep 23 2011(Updated: )
Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long location parameter to the getxml program, aka Bug ID CSCtq46496.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Codec C40 firmware | ||
Cisco TelePresence Codec | ||
Cisco TelePresence Codec | ||
Cisco TelePresence C Series Software | =tc4.0.0 | |
Cisco TelePresence C Series Software | =tc4.0.1 | |
Cisco TelePresence C Series Software | =tc4.0.4 | |
Cisco TelePresence C Series Software | =tc4.1.0 | |
Cisco TelePresence C Series Software | =tc4.1.1 | |
Cisco TelePresence C Series Software | =tc4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2543 is considered a medium severity vulnerability due to its potential to cause denial of service and possibly allow remote code execution.
To fix CVE-2011-2543, upgrade the Cisco TelePresence System Integrator C Series software to a version equal to or greater than TC4.2.0.
CVE-2011-2543 can be exploited to cause a denial of service, which may result in endpoint reboot or process crashes.
CVE-2011-2543 affects Cisco TelePresence Codec C40, C60, C90, and various versions of Cisco TelePresence C Series Software up to TC4.1.2.
CVE-2011-2543 is a remote vulnerability that requires an authenticated user to exploit.