CVE-2017-11309: Buffer Overflow
Published Nov 9, 2017
·Updated
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
Affected Software
1 affected component
Avaya IP Office<10.1.1
Event History
Nov 9, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-11309?
CVE-2017-11309 is a buffer overflow vulnerability in the SoftConsole client in Avaya IP Office before version 10.1.1.
2
What is the severity of CVE-2017-11309?
The severity of CVE-2017-11309 is critical with a CVSS score of 9.6.
3
How does CVE-2017-11309 work?
CVE-2017-11309 allows remote servers to execute arbitrary code by sending a long response, triggering a buffer overflow in the SoftConsole client.
4
Is there a fix for CVE-2017-11309?
Yes, Avaya IP Office version 10.1.1 and above have fixed the buffer overflow vulnerability.
5
What can I do to protect myself from CVE-2017-11309?
To protect yourself from CVE-2017-11309, update your Avaya IP Office to version 10.1.1 or above.