eWeek Security Watch
Advertisement
Advertisement
January 16, 2008 4:31 PM

Cisco Swats Critical CallManager Bug



cisco_logo.gif Switching and routing giant Cisco has shipped a high-priority update to fix a critical flaw affecting its CallManager software product.

The bug, discovered and reported by researchers at TippingPoint's DVLabs, could allow remote attackers to execute arbitrary code on vulnerable installations of Cisco CallManager.

Authentication is not required to exploit this vulnerability, TippingPoint warned in an alert.

The specific flaw exists within the CTL Provider Service, CTLProvider.exe, which binds to TCP port 2444. The service operates over a SSL encrypted transport. Due to a logic flaw in the way data is received in a loop a heap allocation can be arbitrarily overflown, resulting in the control of subsequent heap chunks. This can lead to arbitrary code execution.

Symantec's Deepsight spells out potential attack scenarios:

1. An attacker locates computer hosting the vulnerable application.

2. The attacker constructs and submits malicious data sufficient to trigger this issue. The data will consist of attacker-supplied values for allocating memory, malicious code, replace memory address and possibly NOP instructions.

3. When the application processes the data, attacker-supplied code will execute, completely compromising the affected computer. Failed exploit attempts will likely crash the computer, denying service to legitimate users.

Cisco has confirmed the code execution severity of this bug, noting that it carries a CVSS Base Score of 10.0, the highest score possible.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12486

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise