Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
BID:36675
Info
Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
| Bugtraq ID: | 36675 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2874 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2009 12:00AM |
| Updated: | Oct 14 2009 06:18PM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Presence Server 7.0 Cisco Unified Presence Server 6.0(3) Cisco Unified Presence Server 6.0(2) Cisco Unified Presence Server 6.0 Cisco Unified Presence Server 1.0(3) Cisco Unified Presence Server 1.0(2) Cisco Unified Presence Server 1.0 |
| Not Vulnerable: |
Cisco Unified Presence Server 7.0(4) Cisco Unified Presence Server 6.0(6) |
Discussion
Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
Cisco Unified Presence is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the TimesTenD process to restart, denying service to legitimate users.
Cisco Unified Presence is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the TimesTenD process to restart, denying service to legitimate users.
Exploit / POC
Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Cisco Unified Presence TimesTenD Process Denial of Service Vulnerability
References:
References:
- Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilitie (Cisco)
- Cisco Unified Presence Homepage (Cisco)
- Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilitie (Cisco Systems Product Security Incident Response Team
)