• On BNET: 3 worst things about the iPhone 3G S
August 9, 2007 10:14 AM PDT

Cisco issues 10 security updates

by Dawn Kawamoto

On Wednesday, Cisco Systems issued 10 security updates--three of which address vulnerabilities that can cause "moderate" damage to users' systems.

Although Cisco lists the security flaws as "moderate," it ranks them a "4" on its 5-point severity scale. And in two of the three cases, attackers could gain access without the need to authenticate their identity.

Various versions of the Cisco CallManager and IOS products contain the security flaws, according to Cisco's security advisory.

The Cisco CallManager and IOS products contain security flaws that relate to processing malformed Session Initiation Protocol (SIP) packets. The packets, which are used to create and manage communications in such applications as VoIP and teleconferencing, could trigger a denial-of-service attack as they attempt to handle malicious SIP packets.

Security flaws were also found in Cisco IOS relating to its Next Hop Resolution Protocol packets, as well as its secure copy server operations in some versions of IOS.

Cisco issued an update for numerous versions of IOS, in an effort to patch a security flaw within its Next Hop Resolution Protocol packets and their boundary checking parameters. Malicious attackers could exploit the vulnerabilities by sending a malicious packet to users' systems, triggering a buffer overflow attack.

In the case of the secure copy (SCP) server flaws, an authenticated remote attacker could exploit a flaw in certain versions of Cisco IOS. The vulnerabilities are a result of insufficient enforcement of access restrictions, when performing secure copy operations within IOS. As a result, attackers with minimal read-access privileges could perform SCP operations as though they had maximum privileges.

Dawn Kawamoto covers enterprise security and financial news relating to technology for CNET News. E-mail Dawn.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
advertisement

Can RIM get its mojo back?

The new BlackBerry Tour, carried by Verizon and Sprint, arrives Sunday, even as RIM seems to be losing sales to exclusive devices like the iPhone and Pre.

With Chrome, Google reignites the OS wars

roundup Google Chrome OS, due in 2010, underscores the Web giant's cloud-computing ambitions and opens new competition with Microsoft.
• What Chrome OS has on Windows that Linux doesn't

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right