Cisco Unified Presence Services Can Be Interrupted By Remote Users
|
|
SecurityTracker Alert ID: 1020023
|
|
SecurityTracker URL: http://securitytracker.com/id?1020023
|
|
CVE Reference: CVE-2008-1741
(Links to External Site)
|
Date: May 14 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Cisco Security Advisory
|
Version(s): prior to 6.0(3)
|
Description: Some vulnerabilities were reported in Cisco Unified Presence. A remote user can cause denial of service conditions.
A remote user can send specially crafted IP packets to cause denial of service conditions [CVE-2008-1158, CVE-2008-1740]. Versions
prior to 6.0(1) are affected. Cisco has assigned Cisco Bug IDs CSCsh50164 and CSCsh20972 to these vulnerabilities.
A remote
user can conduct a TCP port scan to trigger a flaw in the SIP Proxy service and cause denial of service conditions [CVE-2008-1741].
Versions 6.0(1) and 6.0(2) are affected. Cisco has assigned Cisco Bug ID CSCsj64533 to this vulnerability.
Cisco discovered
these vulnerabilities.
|
Impact: A remote user can interrupt presence services.
|
Solution: The vendor has issued a fixed version (6.0(3)).
The vendor's advisory is available at:
http://www.cisco.com/warp/public/707/cisco-sa-20080514-cup.shtml
|
Vendor URL: www.cisco.com/warp/public/707/cisco-sa-20080514-cup.shtml (Links to External Site)
|
Cause: State error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 14 May 2008 11:38:09 -0400
Subject: Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities
|
http://www.cisco.com/warp/public/707/cisco-sa-20080514-cup.shtml
CVE-2008-1741
|
|