CVE Vulnerabilities

CVE-2021-1411

Improper Null Termination

Published: Mar 24, 2021 | Modified: Nov 07, 2023
CVSS 3.x
9.9
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Weakness

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

Affected Software

Name Vendor Start Version End Version
Jabber Cisco * 12.1.5 (excluding)
Jabber Cisco 12.5.0 (including) 12.5.4 (excluding)
Jabber Cisco 12.6.0 (including) 12.6.5 (excluding)
Jabber Cisco 12.7.0 (including) 12.7.4 (excluding)
Jabber Cisco 12.8.0 (including) 12.8.5 (excluding)
Jabber Cisco 12.9.0 (including) 12.9.5 (excluding)

Potential Mitigations

References