|
إنضمامك إلي منتديات استراحات زايد يحقق لك معرفة كل ماهو جديد في عالم الانترنت ...
انضم الينا
#1
| ||
| ||
Cisco Unified IP Phone SCCP and SIP protocol vulnerabilities Of the affected system: Cisco Unified IP Phone 7971G Cisco Unified IP Phone 7970G Cisco Unified IP Phone 7961G Cisco Unified IP Phone 7960G Cisco Unified IP Phone 7960 Cisco Unified IP Phone 7941G Cisco Unified IP Phone 7940G Cisco Unified IP Phone 7940 Cisco Unified IP Phone 7936 Cisco Unified IP Phone 7935 Cisco Unified IP Phone 7911G Cisco Unified IP Phone 7906G Description: Cisco Unified IP Phone is the Cisco Unified IP phone solutions. DNS response parsing overflow Running SCCP and SIP firmware for Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices exist in dealing with DNS response buffer overflow* a special DNS response can trigger a buffer overflow vulnerability in a call to execute arbitrary commands. The vulnerability is recorded as CVE-2008-0530 and Cisco Bug ID CSCsj74818 and CSCsk21863. Large ICMP Echo Request Denial of Service Running SCCP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices there is denial of service vulnerability* remote attacker could send oversized ICMP echo request packets lead to a vulnerable IPPBX device to restart. The vulnerability is recorded as CVE-2008-0526 and Cisco Bug ID CSCsh71110. Network Management Network bitsCN_com HTTP Server Denial of Service Running SCCP firmware Cisco Unified IP Phone 7935 and 7936 devices* the internal HTTP server* denial of service vulnerability. If there are loopholes to the phone's TCP 80 port to send a specially crafted HTTP request* it will lead to phone restart. The internal HTTP server only listening on the TCP 80 port. The vulnerability is recorded as CVE-2008-0527 and Cisco Bug ID CSCsk20026. SIP MIME Boundary Overflow Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices in dealing with Multipurpose Internet Mail Extensions (MIME) encoded data buffer overflow vulnerability exists. If there are loopholes to the phone to send a specially crafted SIP message* then it could trigger a buffer overflow to execute arbitrary code on the phone. The vulnerability is recorded as CVE-2008-0528 and Cisco Bug ID CSCsj74786. Telnet Server Overflow Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices exists within the telnet server buffer overflow vulnerability. telnet server is disabled by default* can be configured to allow non-privileged user-level access privileges. If the privileged CRM and non-privileged access to the telnet server is enabled* you must also configure the phone for additional parameters to allow telnet access to the password. If configured to allow non-privileged access to the telephone to enter a special command* then* through the certification of non-privileged user can trigger a buffer overflow to gain privileged access to the phone. The vulnerability is recorded as CVE-2008-0529 and Cisco Bug ID CSCsj78359. Network Alliance www.bitsCN.com SIP Proxy Response Overflow Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices from the SIP proxy in dealing with challenge / response message heap overflow vulnerability exists. If an attacker control of the loopholes phones to register or attempt to register the SIP proxy* or if the attacker can play as an intermediary* you can call to send a malicious challenge / response messages and execute arbitrary commands. The vulnerability is recorded as CVE-2008-0531 and Cisco Bug ID CSCsj74765. Vendor patches: Cisco has therefore issued a security bulletin (cisco-sa-20080213-phone) and the corresponding patch: cisco-sa-20080213-phone: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities Link: http://www.cisco.com/warp/public/707...13-phone.shtml __DEFINE_LIKE_SHARE__ |
مواقع النشر (المفضلة) |
| |
المواضيع المتشابهه | ||||
الموضوع | كاتب الموضوع | المنتدى | مشاركات | آخر مشاركة |
Alpha Protocol | محروم.كوم | منتدى أخبار المواقع والمنتديات العربية والأجنبية | 0 | 05-27-2010 02:10 AM |
11-4 Nokia Call Connect for Cisco 2.01(0329) برنامج لربط الجوال مع الـ Cisco | محروم.كوم | منتدى أخبار المواقع والمنتديات العربية والأجنبية | 0 | 04-11-2010 03:30 PM |
Threads xD Thought Matrix Protocol | محروم.كوم | منتدى أخبار المواقع والمنتديات العربية والأجنبية | 0 | 04-02-2010 01:38 PM |
[ عرض ] : بيع نطاق Protocol.ws بمعنى نظم المواقعـ | محروم.كوم | منتدى أخبار المواقع والمنتديات العربية والأجنبية | 0 | 06-11-2009 11:50 PM |
Way Off-Topic Knowing a phone call before your phone does! | محروم.كوم | منتدى أخبار المواقع والمنتديات العربية والأجنبية | 0 | 04-30-2009 06:20 PM |