منتدى استراحات زايد

منتدى استراحات زايد (http://vb.ma7room.com/index.php)
-   منتدى أخبار المواقع والمنتديات العربية والأجنبية (http://vb.ma7room.com/forumdisplay.php?f=183)
-   -   Cisco Unified IP Phone SCCP and SIP protocol vulnerabilities (http://vb.ma7room.com/showthread.php?t=277170)

محروم.كوم 11-25-2009 06:50 AM

Cisco Unified IP Phone SCCP and SIP protocol vulnerabilities
 
Cisco Unified IP Phone SCCP and SIP protocol vulnerabilities



Of the affected system:
Cisco Unified IP Phone 7971G
Cisco Unified IP Phone 7970G
Cisco Unified IP Phone 7961G
Cisco Unified IP Phone 7960G
Cisco Unified IP Phone 7960
Cisco Unified IP Phone 7941G
Cisco Unified IP Phone 7940G
Cisco Unified IP Phone 7940
Cisco Unified IP Phone 7936
Cisco Unified IP Phone 7935
Cisco Unified IP Phone 7911G
Cisco Unified IP Phone 7906G
Description:
Cisco Unified IP Phone is the Cisco Unified IP phone solutions.
DNS response parsing overflow
Running SCCP and SIP firmware for Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices exist in dealing with DNS response buffer overflow* a special DNS response can trigger a buffer overflow vulnerability in a call to execute arbitrary commands. The vulnerability is recorded as CVE-2008-0530 and Cisco Bug ID CSCsj74818 and CSCsk21863.
Large ICMP Echo Request Denial of Service
Running SCCP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices there is denial of service vulnerability* remote attacker could send oversized ICMP echo request packets lead to a vulnerable IPPBX device to restart. The vulnerability is recorded as CVE-2008-0526 and Cisco Bug ID CSCsh71110.
Network Management Network bitsCN_com

HTTP Server Denial of Service
Running SCCP firmware Cisco Unified IP Phone 7935 and 7936 devices* the internal HTTP server* denial of service vulnerability. If there are loopholes to the phone's TCP 80 port to send a specially crafted HTTP request* it will lead to phone restart. The internal HTTP server only listening on the TCP 80 port. The vulnerability is recorded as CVE-2008-0527 and Cisco Bug ID CSCsk20026.
SIP MIME Boundary Overflow
Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices in dealing with Multipurpose Internet Mail Extensions (MIME) encoded data buffer overflow vulnerability exists. If there are loopholes to the phone to send a specially crafted SIP message* then it could trigger a buffer overflow to execute arbitrary code on the phone. The vulnerability is recorded as CVE-2008-0528 and Cisco Bug ID CSCsj74786.
Telnet Server Overflow
Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices exists within the telnet server buffer overflow vulnerability. telnet server is disabled by default* can be configured to allow non-privileged user-level access privileges. If the privileged CRM and non-privileged access to the telnet server is enabled* you must also configure the phone for additional parameters to allow telnet access to the password. If configured to allow non-privileged access to the telephone to enter a special command* then* through the certification of non-privileged user can trigger a buffer overflow to gain privileged access to the phone.
The vulnerability is recorded as CVE-2008-0529 and Cisco Bug ID CSCsj78359. Network Alliance www.bitsCN.com
SIP Proxy Response Overflow
Running SIP firmware Cisco Unified IP Phone 7940*7940 G* 7960 and 7960G devices from the SIP proxy in dealing with challenge / response message heap overflow vulnerability exists. If an attacker control of the loopholes phones to register or attempt to register the SIP proxy* or if the attacker can play as an intermediary* you can call to send a malicious challenge / response messages and execute arbitrary commands. The vulnerability is recorded as CVE-2008-0531 and Cisco Bug ID CSCsj74765.
Vendor patches:
Cisco has therefore issued a security bulletin (cisco-sa-20080213-phone) and the corresponding patch:
cisco-sa-20080213-phone: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities
Link: http://www.cisco.com/warp/public/707...13-phone.shtml


الساعة الآن 09:36 AM

Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.2 TranZ By Almuhajir


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227