|
Avaya Products PCRE Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA28041
|
|
|
Release Date:
|
2007-12-13
|
|
Last Update:
|
2008-02-29
|
|
Popularity:
|
5,912 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Avaya Converged Communications Server (CCS) 3.x Avaya Modular Messaging 3.x Avaya SIP Enablement Services (SES) 3.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-7225 CVE-2006-7226 CVE-2006-7228 CVE-2006-7230 CVE-2007-1659
|
|
Description: Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise an application using the library.
For more information:
SA27543
SA27582
The vulnerabilities are reported in the following products and versions:
* Avaya Communication Manager (CM 3.x and 4.x)
* Avaya CCS/SES (3.1.1, 3.1.2 and 4.0)
* Avaya AES (4.0.1, 4.1)
* Avaya Intuity AUDIX LX (2.0)
* Avaya Message Networking (3.1)
* Avaya Messaging Storage Server (MSS 3.x)
Solution: Apply patch.
http://support.avaya.com/elmodocs2/qppcn/1625Pu.pdf
Changelog: 2008-02-29: Updated "Solution" section.
Original Advisory: ASA-2007-505:
http://support.avaya.com/elmodocs2/security/ASA-2007-505.htm
Other References: SA27543:
http://secunia.com/advisories/27543/
SA27582:
http://secunia.com/advisories/27582/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|