• On mySimon: Holiday Gifts For Her
August 9, 2007 10:14 AM PDT

Cisco issues 10 security updates

by Dawn Kawamoto
  • Font size
  • Print
  • Post a comment

On Wednesday, Cisco Systems issued 10 security updates--three of which address vulnerabilities that can cause "moderate" damage to users' systems.

Although Cisco lists the security flaws as "moderate," it ranks them a "4" on its 5-point severity scale. And in two of the three cases, attackers could gain access without the need to authenticate their identity.

Various versions of the Cisco CallManager and IOS products contain the security flaws, according to Cisco's security advisory.

The Cisco CallManager and IOS products contain security flaws that relate to processing malformed Session Initiation Protocol (SIP) packets. The packets, which are used to create and manage communications in such applications as VoIP and teleconferencing, could trigger a denial-of-service attack as they attempt to handle malicious SIP packets.

Security flaws were also found in Cisco IOS relating to its Next Hop Resolution Protocol packets, as well as its secure copy server operations in some versions of IOS.

Cisco issued an update for numerous versions of IOS, in an effort to patch a security flaw within its Next Hop Resolution Protocol packets and their boundary checking parameters. Malicious attackers could exploit the vulnerabilities by sending a malicious packet to users' systems, triggering a buffer overflow attack.

In the case of the secure copy (SCP) server flaws, an authenticated remote attacker could exploit a flaw in certain versions of Cisco IOS. The vulnerabilities are a result of insufficient enforcement of access restrictions, when performing secure copy operations within IOS. As a result, attackers with minimal read-access privileges could perform SCP operations as though they had maximum privileges.

Dawn Kawamoto covers enterprise security and financial news relating to technology for CNET News. E-mail Dawn.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission

With eye to the future, try raw photos today

Raw photos are a hassle compared to JPEG. But if you like photography, the list of their image quality advantages is long and getting longer.

Inside the Apple, er, Microsoft Store

Although Redmond's foray into retail bears a big resemblance to Apple's approach, Microsoft has added some distinctive features to draw casual PC buyers and techies alike.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right