Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers.
| Software | From | Fixed in |
|---|---|---|
| alcatel-lucent / omnipcx | 6.2 | 6.2.x |
| alcatel-lucent / omnipcx | 5.0 | 5.0.x |
| alcatel-lucent / omnipcx | - | 9.0.x |
| alcatel-lucent / omnipcx | 8.0 | 8.0.x |
| alcatel-lucent / omnipcx | 7.1 | 7.1.x |
| alcatel-lucent / omnipcx | 7.0 | 7.0.x |