This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Huawei eSpace Desktop products have the following vulnerabilities:
1) The program does not implement comprehensive validity check on the QES file imported into the system, causing the system to exit unexpectedly. (Vulnerability ID: HWPSIRT-2014-1151)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9415.
2) DLL hijacking vulnerability (mfc71enu.dll & mfc71loc.dll). (Vulnerability ID: HWPSIRT-2014-1153)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9416.
3) DLL hijacking vulnerability (tcapi.dll & airpcap.dll). (Vulnerability ID: HWPSIRT-2014-1154)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9416.The CVE ID is same with HWPSIRT-2014-1153.
4) Upon the import of invalid image files in eSpace Meeting, the system exits unexpectedly. (Vulnerability ID: HWPSIRT-2014-1156)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9417.
5) The eSpace Meeting ActiveX control has a memory overflow vulnerability. (Vulnerability ID: HWPSIRT-2014-1157)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9418.HWPSIRT-2014-1151:
Product Name |
Affected Version |
Solved version |
eSpace Desktop |
Versions earlier than eSpace Meeting V100R001C03 |
eSpace Meeting V100R001C03 |
HWPSIRT-2014-1153:
Product Name |
Affected Version |
Solved version |
eSpace Desktop |
Versions earlier than eSpace Desktop V200R003C00 |
eSpace Desktop V200R003C00 |
HWPSIRT-2014-1154:
Product Name |
Affected Version |
Solved version |
eSpace Desktop |
Versions earlier than eSpace Desktop V200R003C00 |
eSpace Desktop V200R003C00 |
HWPSIRT-2014-1156:
Product Name |
Affected Version |
Solved version |
eSpace Desktop |
Versions earlier than eSpace Meeting V100R001C03 |
eSpace Meeting V100R001C03 |
HWPSIRT-2014-1157:
Product Name |
Affected Version |
Solved version |
eSpace Desktop |
eSpace UC V200R002C02 and earlier versions |
eSpace Desktop V200R001C03 |
Attackers may exploit these vulnerabilities to cause the meeting program to exit unexpectedly.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
HWPSIRT-2014-1151:
Base Score: 4.6 (AV:L/AC:L/Au:S/C:N/I:N/A:C)
Temporal Score: 3.8 (E:F/RL:O/RC:C)
HWPSIRT-2014-1153:
Base Score: 4.3 (AV:L/AC:L/Au:S/C:P/I:P/A:P)
Temporal Score: 3.5 (E:F/RL:O/RC:C)
HWPSIRT-2014-1154:
Base Score: 4.3 (AV:L/AC:L/Au:S/C:P/I:P/A:P)
Temporal Score: 3.5 (E:F/RL:O/RC:C)
HWPSIRT-2014-1156:
Base Score: 4.6 (AV:L/AC:L/Au:S/C:N/I:N/A:C)
Temporal Score: 3.8 (E:F/RL:O/RC:C)
HWPSIRT-2014-1157:
Base Score: 1.7 (AV:L/AC:L/Au:S/C:N/I:N/A:P)
Temporal Score: 1.4 (E:F/RL:O/RC:C)
HWPSIRT-2014-1151: When users import normal QES files on the Poll page, the system displays questionnaires; when users import abnormal QES files, the questionnaires are displayed in data meeting, causing the program to exit unexpectedly.
HWPSIRT-2014-1153: To call the system DLL, a program calls and runs a forged DLL. As a result, the system DLL is hijacked. Attackers may hijack the DLL of the MFC and run malicious code to undermine system security.
HWPSIRT-2014-1154: To call the system DLL, a program calls and runs a forged DLL. As a result, the system DLL is hijacked. Attackers may hijack the DLL of the MFC and run malicious code to undermine system security.
HWPSIRT-2014-1156: When users insert normal image files on whiteboards, the system displays the images normally; when users import abnormal image files, the images are displayed in data meeting, causing the program to exit unexpectedly.
HWPSIRT-2014-1157: The eSpaceStatusCtrl.dll module has a memory overflow vulnerability, which may cause a crash when exploited.
This vulnerability was found by Gjoko Krstic. Huawei PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Huawei express our appreciation for Gjoko Krstic’s concerns on Huawei products.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2015-03-20 V1.1 UPDATED Add the CVE ID for the vulnerabilities
2014-12-17 V1.0 INITIAL
None