Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
BID:36498
Info
Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
| Bugtraq ID: | 36498 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2865 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2009 12:00AM |
| Updated: | Sep 23 2009 06:50PM |
| Credit: | Cisco |
| Vulnerable: |
Cisco IOS 12.4YA Cisco IOS 12.4XZ Cisco IOS 12.4XY Cisco IOS 12.4XW |
| Not Vulnerable: |
Cisco IOS 12.4(24)T2 Cisco IOS 12.4(22)T3 Cisco IOS 12.4(20)YA1 Cisco IOS 12.4(20)T4 Cisco IOS 12.4(15)XZ1 Cisco IOS 12.4(15)XY4 Cisco IOS 12.4(11)XW8 |
Discussion
Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
Cisco IOS devices configured for Unified Communications Manager Express and the Extension Mobility feature are prone to a buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code or to cause denial-of-service conditions.
This issue is documented by Cisco Bug ID CSCsq58779.
Cisco IOS devices configured for Unified Communications Manager Express and the Extension Mobility feature are prone to a buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code or to cause denial-of-service conditions.
This issue is documented by Cisco Bug ID CSCsq58779.
Exploit / POC
Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory along with fixes. Please see the referenced advisory for details.
Solution:
The vendor has released an advisory along with fixes. Please see the referenced advisory for details.
References
Cisco Unified Communications Manager Express Extension Mobility Buffer Overflow Vulnerability
References:
References:
- Cisco Homepage (Cisco)
- Cisco Security Advisory: Cisco Unified Communications Manager Express Vulnerabil (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco Unified Communications Manager Express Vulnerabil (Cisco)