Huawei eSpace 1.1.11.103 Meeting Heap Overflow
Posted by deepcore on May 21, 2019 – 8:10 am
Huawei eSpace version 1.1.11.103 Meeting suffers from a heap-based memory overflow vulnerability when parsing large amount of bytes to the ‘strNum’ string parameter in GetNameyNum() in ‘ContactsCtrl.dll’ and ‘strName’ string parameter in SetUserInfo() in eSpaceStatusCtrl.dll library, resulting in heap memory corruption. An attacker can gain access to the system of the affected node and execute arbitrary code.
Post a reply
You must be logged in to post a comment.