Description
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
Affected products
- Cisco / unified_communications_manager4.1 – 4.1
- Cisco / unified_communications_manager4.2 – 4.2
- Cisco / unified_communications_manager4.3 – 4.3
- Cisco / unified_communications_manager5.1 – 5.1
- Cisco / unified_communications_manager5.1 – 5.1
- Cisco / unified_communications_manager5.1 – 5.1
- Cisco / unified_communications_manager5.1 – 5.1
- Cisco / unified_communications_manager5.1 – 5.1
- Cisco / unified_communications_manager6.0 – 6.0
- Cisco / unified_communications_manager6.0 – 6.0
- Cisco / unified_communications_manager6.0 – 6.0
- Cisco / unified_communications_manager6.1 – 6.1
- Cisco / unified_communications_manager6.1 – 6.1
References
- VENDOR_ADVISORYhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtml
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/42410
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/1533
- MISChttp://www.securityfocus.com/bid/29221
- VENDOR_ADVISORYhttp://secunia.com/advisories/30238
- MISChttp://securitytracker.com/id?1020022