Joined: 18 Jan 2006 Posts: 207 Location: Singapore
Posted: 01/20/06 - 14:11 Post subject: Cisco plugs IP telephony and router security holes
Quote:
Cisco has fixed updates to address flaws in its IP telephony software and router hardware that create a means to conduct denial of service attacks against vulnerable systems. Neither flaw is particularly easy to exploit but both merit attention.
Security weaknesses in various flavours of Cisco CallManager 3.x and 4.x create a means to consume a large amount of memory and CPU resources via multiple open connections to port 2000. A separate flaw in the processing of connections to ports 2001, 2002, and 7727 might force Cisco CallManager to reboot.....