Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Link | Tags |
---|---|
http://secunia.com/advisories/36499 | third party advisory broken link |
http://www.securityfocus.com/bid/36152 | broken link third party advisory vdb entry |
http://secunia.com/advisories/36498 | third party advisory broken link |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtml | patch vendor advisory broken link |
http://osvdb.org/57456 | vdb entry broken link |
http://www.securitytracker.com/id?1022775 | broken link third party advisory vdb entry |