Alcatel-Lucent OmniVista 4760 HTTP Proxy Buffer Overflow Vulnerability


Description   A vulnerability has been identified in Alcatel-Lucent OmniVista 4760, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the HTTP proxy when processing overly long requests, which could allow remote unauthenticated attackers to crash an affected service or compromise a vulnerable system via a specially crafted HTTP request.
     
Vulnerable Products   Vulnerable Software:
Alcatel-Lucent OmniVista 4760 versions prior to 5.1.06.03.c_Patch3
     
Solution   Upgrade to versions 5.1.06.03.c_Patch3.
     
CVE   CVE-2010-3281
     
References   http://www.nruns.com/_downloads/nruns-SA-2010-002.pdf
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2010-09-21 

 Target Type 
Server 

 Possible exploit 
Local & Remote