First published: Fri Nov 08 2013(Updated: )
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sametime | =8.5.2 | |
IBM Sametime | =8.5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3986 has a medium severity rating due to its ability to cause a denial of service.
To fix CVE-2013-3986, update IBM Lotus Sametime to version 8.5.2.2 or later.
CVE-2013-3986 allows remote attackers to perform denial of service attacks by crashing the WebPlayer Firefox extension during an AV session.
Versions 8.5.2 and 8.5.2.1 of IBM Lotus Sametime are affected by CVE-2013-3986.
There are no official workarounds for CVE-2013-3986; upgrading to a patched version is recommended.