CVE-2008-1742
published 2008-05-16CVE-2008-1742: Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to…
PriorityP429high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.18%
64.4th percentile
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pg7h-qxx2-2q2c: Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2008-1742 [HIGH] GHSA-pg7h-qxx2-2q2c: Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2008-05-14·CVSS 7.8
CVE-2008-1742 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager, formerly Cisco CallManager,
contains multiple denial of service (DoS) vulnerabilities that may cause an
interruption in voice services, if exploited. These vulnerabilities were
discovered internally by Cisco. The following Cisco Unified Communications
Manager services are affected:
Certificate Trust List (CTL) Provider
Certificate Authority Proxy Function (CAPF)
Session Initiation Protocol (SIP)
Simple Network Management Protocol (SNMP) Trap
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are
available.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecuri
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2008-1742 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2008-1742: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco. The following Cisco Unified Communications Manager services are affected: Certificate Trust List (CTL) Provider Certificate Authority Proxy Function (CAPF) Session Initiation Protocol (SIP) Simple Network Management Protocol (SNMP) Trap Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCsj80609, CSCsi98433, CSCsk46770, CSCsi48115, CSCsk46944
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/30238http://securitytracker.com/id?1020022http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtmlhttp://www.securityfocus.com/bid/29221http://www.vupen.com/english/advisories/2008/1533https://exchange.xforce.ibmcloud.com/vulnerabilities/42410http://secunia.com/advisories/30238http://securitytracker.com/id?1020022http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtmlhttp://www.securityfocus.com/bid/29221http://www.vupen.com/english/advisories/2008/1533https://exchange.xforce.ibmcloud.com/vulnerabilities/42410
2008-05-16
Published