Description: Two vulnerabilities have been reported in Cisco Unified Communications Manager (CUCM), which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
1) A boundary error in the Centralized TFTP File Locator Service of CUCM TFTP when processing filenames can be exploited to cause a buffer overflow.
Successful exploitation may allow execution of arbitrary code.
2) An error when processing SIP INVITE messages can be exploited to cause a resource exhaustion by e.g. flooding a CUCM system with SIP INVITE messages to default port 5060/UDP.
Please see the vendor's advisory for a list of affected versions.
Solution: Update to the latest versions (see vendor's advisory).
Provided and/or discovered by: Reported by the vendor.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.