CVE Vulnerabilities

CVE-2021-1418

Improper Null Termination

Published: Mar 24, 2021 | Modified: Mar 29, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Weakness

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

Affected Software

Name Vendor Start Version End Version
Jabber Cisco 12.5.0 *
Jabber Cisco 12.6.0 *
Jabber Cisco 12.7.0 *
Jabber Cisco 12.8.0 *
Jabber Cisco 12.9.0 *
Jabber Cisco * 12.9.0
Jabber Cisco * 12.9.0
Jabber Cisco 12.9.0 *
Jabber Cisco * *
Jabber Cisco * *

Potential Mitigations

References