vendor:
eSpace
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: eSpace
Affected Version From: eSpace 1.1.11.103 (aka eSpace ECS, eSpace Desktop, eSpace Meeting, eSpace UC), eSpace UC V200R002C02
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2014-9418
CPE: Program Files:eSpace-ecs:ContactsCtrl.dll, Program Files:eSpace-ecs:eSpaceStatusCtrl.dll
Platforms Tested: Microsoft Windows 7 Professional
2014
Huawei eSpace Meeting ContactsCtrl.dll and eSpaceStatusCtrl.dll ActiveX Heap Overflow
eSpace Meeting suffers from a heap-based memory overflow vulnerability when parsing large amount of bytes to the 'strNum' string parameter in GetNameyNum() in 'ContactsCtrl.dll' and 'strName' string parameter in SetUserInfo() in eSpaceStatusCtrl.dll library, resulting in heap memory corruption. An attacker can gain access to the system of the affected node and execute arbitrary code.
Mitigation:
Apply the patched version V200R001C03