Buffer over-read in Polycom, Inc. products - CVE-2017-12857
Published: September 12, 2017
Vulnerability identifier: #VU8242
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12857
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Polycom, Inc.
Affected software:
RealPresence Trio
VVX
SoundStation IP
RealPresence Trio
VVX
SoundStation IP
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The weakness exists due to buffer over-read. A remote attacker can upload a specially crafted file containing null characters and obtain potentially sensitive information from uninitialized system memory.
Successful exploitation of the vulnerability results in information disclosure.
The weakness exists due to buffer over-read. A remote attacker can upload a specially crafted file containing null characters and obtain potentially sensitive information from uninitialized system memory.
Successful exploitation of the vulnerability results in information disclosure.
How to mitigate CVE-2017-12857
The vulnerability is addressed in the following version: UCS 4.0.12, 5.6.0, 5.5.2, 5.4.7, 5.4.5.