Title : Alcatel-Lucent OmniSwitch Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2346 CVE ID : CVE-2008-4383 CWE ID : CWE-119
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-12
Technical Description
A vulnerability has been identified in Alcatel-Lucent OmniSwitch, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable device. This issue is caused by a buffer overflow error in the embedded management web server when processing HTTP GET requests with an overly long "Session" cookie, which could allow an attacker to cause a crash or execute arbitrary code via a specially crafted packet.