Vulnerability Note VU#145825
SISCO OSI stack fails to properly handle malformed packets
Overview
A vulnerability exists in the SISCO OSI stack. If this vulnerability is successfully exploited, an attacker could cause a denial-of-service condition.
Description
The SISCO OSI stack is a component of the SISCO MMS-EASE, ICCP Toolkit for MMS-EASE, AX-S4 MMS and AX-S4 ICCP products. The SISCO OSI stack fails to properly handle malformed packets. A remote attacker may be able to trigger this vulnerability by sending a specially crafted series of packets to a vulnerable SISCO OSI stack installation. Note that a valid connection is needed to trigger this vulnerability. |
Impact
A remote attacker can cause the OSI stack to terminate abnormally resulting in a denial-of-service condition requiring an application using the SISCO OSI stack and the SISCO OSI stack itself to be restarted. |
Solution
Upgrade or Patch accordingly |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| SISCO - Systems Integration Specialists Company, Inc. | Affected | 21 Sep 2006 | 12 Jan 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.sisconet.com/home.htm
- http://www.sisconet.com/contact.htm
- http://secunia.com/advisories/23819/
- http://www.securityfocus.com/bid/22095
Credit
Thanks to Matthew D. Franz for researching and reporting this vulnerability.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CVE-2006-6489
- Date Public: 17 Jan 2007
- Date First Published: 17 Jan 2007
- Date Last Updated: 26 Jan 2007
- Severity Metric: 0.50
- Document Revision: 39
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.