Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
BID:14255
Info
Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 14255 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | Mark Dowd, Mike Lynn, David Maynor, Neel Mehta, and Alex Wheeler of ISS X-Force are credited with the discovery and research of this vulnerability. |
| Vulnerable: |
Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 |
Discussion
Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
The CallManager aupair service is susceptible to an unspecified remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed size memory buffer.
This issue is documented in Cisco bug CSCsa75554, which is available to Cisco customers.
This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely result in crashing the affected process, denying service to legitimate users.
This issue was originally documented in BID 14227.
The CallManager aupair service is susceptible to an unspecified remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed size memory buffer.
This issue is documented in Cisco bug CSCsa75554, which is available to Cisco customers.
This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely result in crashing the affected process, denying service to legitimate users.
This issue was originally documented in BID 14227.
Exploit / POC
Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
References
Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability
References:
References:
- CallManager Product Page (Cisco)
- Cisco CallManager Memory Handling Vulnerabilities (Cisco)
- Cisco VoIP Call Manager Remote Compromise (Internet Security Systems)