Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
BID:14251
Info
Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14251 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | Jeff Fay from PatchAdvisor reported this vulnerability to the vendor. |
| Vulnerable: |
Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 |
Discussion
Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
The CallManager CTI Manager service is susceptible to a remote denial of service vulnerability.
This issue is documented in Cisco bug CSCee00116, which is available to Cisco customers.
This issue may be exploited to cause the affected application to restart, denying service to legitimate users.
This issue was originally documented in BID 14227.
The CallManager CTI Manager service is susceptible to a remote denial of service vulnerability.
This issue is documented in Cisco bug CSCee00116, which is available to Cisco customers.
This issue may be exploited to cause the affected application to restart, denying service to legitimate users.
This issue was originally documented in BID 14227.
Exploit / POC
Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
No exploit is required.
A command sufficient to exploit this vulnerability was given:
wget http://www.example.com:2000
No exploit is required.
A command sufficient to exploit this vulnerability was given:
wget http://www.example.com:2000
Solution / Fix
Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
References
Cisco CallManager CTI Manager Remote Denial Of Service Vulnerability
References:
References:
- CallManager Product Page (Cisco)
- Cisco Call Manager Memory Corruption Vulnerability (PatchAdvisor)
- Cisco CallManager Memory Handling Vulnerabilities (Cisco)