SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#495275

Cisco CallManager contains memory leak

Overview

The Cisco Call Manager contains a vulnerability that could permit an intruder to crash the Call Manager.

I. Description

The Cisco Call Manageris software to manage telephone calls in a mixed data and voice environment. Specifically the Cisco Call Manager "extends enterprise telephony features and functions to packet telephony network devices such as IP phones, media processing devices, voice-over-IP (VoIP) gateways, and multimedia applications.1" The software contains a vulnerability that allows could permit an intruder to consume memory until the system crashes. Quoting from Cisco's Security Advisory:

    The Cisco CallManager, running certain software releases, has a vulnerability wherein a memory leak in the CTI Framework authentication can cause the server to crash and result in a reload. This vulnerability can be exploited to initiate a denial of service (DoS) attack.


It may be possible for the vulnerability to be triggered accidentally. For more information, see the vendor statement from Cisco below.

II. Impact

An intruder could interrupt the normal function of the Cisco Call Manager, causing it to crash and reload.

III. Solution

Upgrade to a more recent version of Cisco Call Manager, as described in http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtml.

Systems Affected

VendorStatusDate NotifiedDate Updated
Cisco Systems Inc.Vulnerable9-Aug-2002

References


http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtml
http://www.cisco.com/warp/public/cc/pd/nemnsw/callmn/index.shtml
http://www.cisco.com/warp/public/180/prod_plat/cust_cont/icm/cti.html
http://www.securityfocus.com/bid/4370

Credit

Thanks to Cisco Systems Product Security Incident Response Team for reporting this vulnerability.

This document was written by Shawn V Hernan, based on information provided by Cisco Systems.

Other Information

Date Public:2002-03-27
Date First Published:2002-08-10
Date Last Updated:2002-08-10
CERT Advisory: 
CVE-ID(s):CAN-2002-0505
NVD-ID(s):CAN-2002-0505
US-CERT Technical Alerts: 
Metric:5.62
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader