Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products
The vulnerability is due to unsafe code generation by the ASN1C compiler when creating ASN.1 translation functions that are subsequently included within affected Cisco products. An attacker could exploit this vulnerability by submitting a malicious Abstract Syntax Notation One (ASN.1) encoded message designed to trigger the issue to an affected function.
US-CERT has released Vulnerability Note VU#790839 to document the issue.
Cisco will release software updates that address this vulnerability. This advisory is available at the following link:
http://ift.tt/2ayoStw
The vulnerability is due to unsafe code generation by the ASN1C compiler when creating ASN.1 translation functions that are subsequently included within affected Cisco products. An attacker could exploit this vulnerability by submitting a malicious Abstract Syntax Notation One (ASN.1) encoded message designed to trigger the issue to an affected function.
US-CERT has released Vulnerability Note VU#790839 to document the issue.
Cisco will release software updates that address this vulnerability. This advisory is available at the following link:
http://ift.tt/2ayoStw
Security Impact Rating: Critical
CVE: CVE-2016-5080
from Cisco Security Advisory http://ift.tt/2ayoStw