CVE-2009-1157
published 2009-04-09CVE-2009-1157: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.66%
84.0th percentile
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_5500 | — | — |
| cisco | adaptive_security_appliance_5500 | — | — |
| cisco | adaptive_security_appliance_5500 | — | — |
| cisco | adaptive_security_appliance_5500 | — | — |
| cisco | adaptive_security_appliance_5500 | — | — |
| cisco | asa_adaptive_security_appliance_and_cisco_pix_security_appliances | — | — |
| cisco | pix | — | — |
| cisco | pix | — | — |
| cisco | pix | — | — |
| cisco | pix | — | — |
| cisco | pix | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
vendor_cisco·2009-04-08·CVSS 7.8
CVE-2009-1155 [HIGH] CWE-264 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive
Security Appliances and Cisco PIX Security Appliances. This security advisory
outlines the details of these vulnerabilities:
VPN Authentication Bypass when Account Override Feature is Used
vulnerability
Crafted HTTP packet denial of service (DoS) vulnerability
Crafted TCP Packet DoS vulnerability
Crafted H.323 packet DoS vulnerability
SQL*Net packet DoS vulnerability
Access control list (ACL) bypass vulnerability
Workarounds are available for some of the vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090408-asa.
Red Hat
kernel: splice local denial of service
vendor_redhat·2009-04-06·CVSS 4.7
CVE-2009-1961 [MEDIUM] kernel: splice local denial of service
kernel: splice local denial of service
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
Statement: This issue does not affect versions of Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise Linux MRG 2.
This issue was fixed in Red Hat Enterprise Linux MRG 1 via https://rhn.redhat.com/errata/RHSA-2009-1157.html.
Cisco
Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
vendor_cisco
CVE-2009-1157 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
CVE-2009-1157: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. This security advisory outlines the
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCsx47543, CSCsv52239, CSCsy22484, CSCsx32675, CSCsw51809
GHSA
GHSA-gfg2-qwmm-84qp: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7
ghsa_unreviewed·2022-05-02
CVE-2009-1157 [HIGH] GHSA-gfg2-qwmm-84qp: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet.
No detection rules found.
Bugzilla
CVE-2009-5065 CVE-2011-1156 CVE-2011-1157 CVE-2011-1158 python-feedparser: multiple flaws corrected in version 5.0.1
bugzilla·2011-03-14·CVSS 4.3
CVE-2009-5065 [MEDIUM] CVE-2009-5065 CVE-2011-1156 CVE-2011-1157 CVE-2011-1158 python-feedparser: multiple flaws corrected in version 5.0.1
CVE-2009-5065 CVE-2011-1156 CVE-2011-1157 CVE-2011-1158 python-feedparser: multiple flaws corrected in version 5.0.1
The Python Feed Parser program (python-feedparser) recently released version 5.0.1 with the following fixes:
* Fix issue 91 (invalid text in XML declaration causes sanitizer to crash)
* Fix issue 254 (sanitization can be bypassed by malformed XML comments)
* Fix issue 255 (sanitizer doesn't strip unsafe URI schemes)
Giving the code a quick look, I don't believe the latter two issues affected 4.1 (possibly introduced in the 5.0 release). The first issue was reported against version 4.1 so would affect what we currently ship in Fedora and EPEL.
Version 5.0.1 corrects these flaws. It may be worthwhile to update to the latest version as the 5.0 release corrected a number of
Bugzilla
CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
bugzilla·2010-04-23·CVSS 5.8
CVE-2009-2901 [MEDIUM] CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=585331
Please note:
http://osvdb.org/53445http://secunia.com/advisories/34607http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtmlhttp://www.securityfocus.com/bid/34429http://www.securitytracker.com/id?1022015http://www.vupen.com/english/advisories/2009/0981http://osvdb.org/53445http://secunia.com/advisories/34607http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtmlhttp://www.securityfocus.com/bid/34429http://www.securitytracker.com/id?1022015http://www.vupen.com/english/advisories/2009/0981
2009-04-09
Published