|
Cisco Unified Communications Manager to sårbarheder
|
|
|
|
|
Secunia Advisory:
|
SA26043
|
|
|
Udsendt:
|
2007-07-12
|
|
|
Kritisk:
|

Moderat kritisk
|
|
Betydning:
|
DoS Systemadgang
|
|
Hvor:
|
Fra Lokalt Netværk
|
|
Løsning Status:
|
Producent Patch
|
|
| Software: | Cisco Unified CallManager 3.x Cisco Unified CallManager 4.x Cisco Unified CallManager 5.x Cisco Unified Communications Manager 4.x Cisco Unified Communications Manager 5.x
|
| | CVE reference: | CVE-2006-5277 (Secunia mirror) CVE-2006-5278 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Beskrivelse: Der er rapporteret nogle sårbarheder i Cisco Unified Communications Manager (CUCM), som kan udnyttes af ondsindede personer til at udføre et DoS (Denial of Service) eller potentielt kompromittere et sårbart system.
1) En off-by-one fejl i Certificate Trust List Provider servicen (CTLProvider.exe) kan udnyttes til at forårsage et heap-baseret buffer overflow ved at sende specielt udformede pakker til servicen (som standard port 2444/TCP).
Note: Denne sårbarhed berører ikke CUCM 3.x.
2) Et heltals-overflow i Real-Time Information Server (RIS) Data Collector servicen (RisDC.exe) kan udnyttes til at forårsage et heap-baseret buffer overflow ved at sende specielt udformede pakker til servicen (som standard port 2556/TCP).
Succesfuld udnyttelse kan muliggøre eksekvering af vilkårlig kode.
Løsning: Installér opdaterede versioner.
Sårbarhed #1 er rettet i CUCM version 4.1(3)SR5, 4.2(3)SR2, 4.3(1)SR1 og 5.1(2).
Sårbarhed #2 er rettet i CUCM version 3.3(5)SR2b, 4.1(3)SR5, 4.2(3)SR2, 4.3(1)SR1 og 5.1(2).
Se producentens advisory for en detaljeret patch-matrix.
Rapporteret af / Kredit: IBM Internet Security Systems X-Force
Original Advisory: Cisco:
http://www.cisco.com/warp/public/707/cisco-sa-20070711-cucm.shtml
IBM Internet Security Systems:
1) http://www.iss.net/threats/270.html
2) http://www.iss.net/threats/271.html
Dybdegående Løsning: The "Dybdegående Løsning" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
24 Relaterede Secunia Advisories, displaying 10
|
|
|
1. Cisco Unified Communications Manager CTL Provider Service buffer overflow
|
|
2. Cisco Security Agent uspecificeret system-driver buffer overflow
|
|
3. Cisco Unified Communications Manager to sårbarheder
|
|
4. Cisco CallManager godkendelses-header hijacking
|
|
5. Cisco CallManager / CUCM cross-site scripting og SQL-indsættelse
|
|
6. Cisco Unified Communications Manager SIP pakke-håndtering sårbarhed
|
|
7. Cisco Products Java Secure Socket Extension SSL/TLS-forespørgsel Denial of Service
|
|
8. Cisco Unified Communications Manager og Presence Server sikkerhedsomgåelse
|
|
9. Cisco CallManager cross-site scripting
|
|
10. Cisco produkter Crypto-bibliotek Denial of Service
|
Vis alle relaterede advisories
|
|
|
Send Feedback to Secunia
|
|
Hvis du har ny information angående dette Secunia advisory eller et produkt i vores database, så send det venligst til os. Du kan sende det til os enten ved at bruge vores web formular eller ved at sende det til vuln@secunia.com.
Ideer, foreslag og andet feedback er også meget velkommen.
|
|
|
|