|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2009-25

Cisco Unified Communications Manager SIP Denial of Service Vulnerability

Original Issue Date: October 7, 2009

Severity Rating: Medium

Affected Softwares

  • Cisco Unified Communications Manager versions prior to 5.1(3g)
  • Cisco Unified Communications Manager versions prior to 6.1(4)
  • Cisco Unified Communications Manager versions prior to 7.0(2a)su1
  • Cisco Unified Communications Manager versions prior to 7.1(2)

Overview

Cisco Unified Communications Manager contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service condition.

Description

This vulnerability is due to errors in processing malformed SIP messages. An unauthenticated, remote attacker could exploit this vulnerability by sending specially crafted SIP messages to the vulnerable system. When processed, the messages could trigger an error condition that could result in the failure and restart of the Cisco Unified Communications Manager service, causing denial of service condition (DoS).

Solution

Upgrade to Cisco Unified Communications Manager version 5.1(3g), 6.1(4), 7.0(2a)su1 or 7.1(2) , as suggested by vendor as follows: http://www.cisco.com/public/sw-center/sw-usingswc.shtml

Vendor Information

CISCO
http://www.cisco.com/warp/public/707/cisco-sa-20090923-cm.shtml

CVE Name
CVE-2009-2864

References

CISCO
http://www.cisco.com/warp/public/707/cisco-sa-20090923-cm.shtml

VUPEN
http://www.vupen.com/english/advisories/2009/2757

Secunia
http://secunia.com/advisories/36836/

SecurityFocus
http://www.securityfocus.com/bid/36496/

SecurityTracker
http://securitytracker.com/alerts/2009/Sep/1022931.html

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

10-Jul-2011