Cisco Swats Critical CallManager Bug
The bug, discovered and reported by researchers at TippingPoint's DVLabs, could allow remote attackers to execute arbitrary code on vulnerable installations of Cisco CallManager. Authentication is not required to exploit this vulnerability, TippingPoint warned in an alert. The specific flaw exists within the CTL Provider Service, CTLProvider.exe, which binds to TCP port 2444. The service operates over a SSL encrypted transport. Due to a logic flaw in the way data is received in a loop a heap allocation can be arbitrarily overflown, resulting in the control of subsequent heap chunks. This can lead to arbitrary code execution. Symantec's Deepsight spells out potential attack scenarios: 1. An attacker locates computer hosting the vulnerable application. Cisco has confirmed the code execution severity of this bug, noting that it carries a CVSS Base Score of 10.0, the highest score possible. |

Switching and routing giant Cisco has shipped a high-priority update to fix a critical flaw affecting its CallManager software product.