Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (application-optimization handler reload) via a crafted SharePoint application, aka Bug ID CSCue47674.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/67696 | vdb entry third party advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=34395 | vendor advisory |
http://www.securitytracker.com/id/1030307 | vdb entry third party advisory |
http://secunia.com/advisories/58806 | third party advisory permissions required |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3285 | vendor advisory |