CVE-2007-4292
published 2007-08-09CVE-2007-4292: Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1)…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_and_cisco_unified_communications_manager | — | — |
Cisco
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
vendor_cisco·2007-08-08·CVSS 10.0
CVE-2007-4291 [CRITICAL] CWE-399 Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Multiple voice-related vulnerabilities are identified in Cisco IOS
software, one of which is also shared with Cisco Unified Communications
Manager. These vulnerabilities pertain to the following protocols or features:
Session Initiation Protocol (SIP)
Media Gateway Control Protocol (MGCP)
Signaling protocols H.323, H.254
Real-time Transport Protocol (RTP)
Facsimile reception
Cisco has made free software available to address these
vulnerabilities for affected customers. Fixed Cisco IOS software listed in the
Software Versions and Fixes section contains fixes for all
vulnerabilities mentioned in this advisory.
There are no workarounds available to mitigate the effects of any of
the vulnerabilities apart from
Cisco
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
vendor_cisco
CVE-2007-4292 Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
CVE-2007-4292: Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Multiple voice-related vulnerabilities are identified in Cisco IOS software, one of which is also shared with Cisco Unified Communications Manager. These vulnerabilities pertain to the following protocols or features: Session Initiation Protocol (SIP) Media Gateway Control Protocol (MGCP) Signaling protocols H.323, H.254 Real-time Transport Protocol (RTP) Facsimile reception Cisco has made free software available to address these vulnerabilities for affected customers. Fixed Cisco IOS software listed in the Software Versions and Fixes section contains fixes for all vulnerabilities mentioned in this advisory. There are no
CWE: CWE-399, CWE-94, CWE-399, CWE-94
Bug IDs: CSCeb21064, CSCsb24007, CSCsc6024
GHSA
GHSA-847m-hhjw-9pj4: Multiple memory leaks in Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2007-4292 [HIGH] GHSA-847m-hhjw-9pj4: Multiple memory leaks in Cisco IOS 12
Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/36670http://osvdb.org/36671http://osvdb.org/36672http://osvdb.org/36673http://osvdb.org/36674http://osvdb.org/36675http://osvdb.org/36676http://secunia.com/advisories/26363http://securitytracker.com/id?1018533http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtmlhttp://www.securityfocus.com/bid/25239http://www.vupen.com/english/advisories/2007/2816https://exchange.xforce.ibmcloud.com/vulnerabilities/35890https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5781http://osvdb.org/36670http://osvdb.org/36671http://osvdb.org/36672http://osvdb.org/36673http://osvdb.org/36674http://osvdb.org/36675http://osvdb.org/36676http://secunia.com/advisories/26363http://securitytracker.com/id?1018533http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtmlhttp://www.securityfocus.com/bid/25239http://www.vupen.com/english/advisories/2007/2816https://exchange.xforce.ibmcloud.com/vulnerabilities/35890https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5781
2007-08-09
Published