Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
BID:4370
Info
Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
| Bugtraq ID: | 4370 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2002 12:00AM |
| Updated: | Mar 27 2002 12:00AM |
| Credit: | Published in a Cisco Security Advisory. |
| Vulnerable: |
Cisco Call Manager 3.1 Cisco Call Manager 3.0 |
| Not Vulnerable: |
Cisco Call Manager 3.1 (3a) |
Discussion
Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
Cisco CallManager is the software based call processing component of the Cisco IP Telephony solution. A denial of service condition has been reported in some versions of the CallManager software.
If a user does not properly authenticate when using Call Telephony Integration (CTI), a memory leak may occur. This may result in the vulnerable process crashing and reloading.
Cisco CallManager is the software based call processing component of the Cisco IP Telephony solution. A denial of service condition has been reported in some versions of the CallManager software.
If a user does not properly authenticate when using Call Telephony Integration (CTI), a memory leak may occur. This may result in the vulnerable process crashing and reloading.
Exploit / POC
Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
Solution:
Cisco recommends that all users upgrade to version 3.1(3a), available from the vendor.
Solution:
Cisco recommends that all users upgrade to version 3.1(3a), available from the vendor.
References
Cisco CallManager CTI Memory Leak Denial of Service Vulnerability
References:
References:
- CallManager Product Homepage (Cisco Systems)