Avaya IP Office Apache HTTP Server ByteRange Filter Denial of Service Vulnerability


Description   Avaya has acknowledged a vulnerability in Avaya IP Office, which can be exploited by malicious people to cause a DoS (Denial of Service).
For more information:
SA45606
The vulnerability is reported in versions 6.x and 7.x.
     
Vulnerable Products   Vulnerable Software:
Avaya IP Office 6.xAvaya IP Office 7.x
     
Solution   Upgrade to version 9.0 or later.
     
CVE   CVE-2011-3192
     
References   ASA-2011-281:
https://downloads.avaya.com/css/P8/documents/100148618
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2015-03-31 

 Target Type 
Server 

 Possible exploit 
Remote