vendor:
eSpace Meeting
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: eSpace Meeting
Affected Version From: eSpace 1.1.11.103
Affected Version To: eSpace 1.1.11.103
Patch Exists: YES
Related CWE: CVE-2014-9417
CPE: a:huawei:espace_meeting
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 7 Professional
2014
Huawei eSpace Meeting Image File Format Handling Buffer Overflow Vulnerability
eSpace Meeting conference whiteboard functionality is vulnerable to a buffer overflow issue when inserting known image file formats. Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Mitigation:
Upgrade to the latest version of eSpace Meeting (V100R001C03) to mitigate this vulnerability.