CVE-2014-2171: Buffer Overflow
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2171?
CVE-2014-2171 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2014-2171?
To fix CVE-2014-2171, update the affected Cisco TelePresence software to version 6.0.1 or later for TC Software and 6.0.2 or later for TE Software.
Which versions of Cisco software are affected by CVE-2014-2171?
CVE-2014-2171 affects Cisco TelePresence TC Software versions 4.x through 6.x before 6.0.1 and TE Software versions 4.x and 6.0.x before 6.0.2.
Can CVE-2014-2171 be exploited remotely?
Yes, CVE-2014-2171 can be exploited remotely through crafted SIP packets.
What is a heap-based buffer overflow in relation to CVE-2014-2171?
A heap-based buffer overflow in CVE-2014-2171 occurs when a program writes more data to a buffer on the heap than it can hold, potentially allowing an attacker to execute arbitrary code.