CVE-2010-0583Missing Release of Memory after Effective Lifetime in Cisco IOS

CWE-3994 documents4 sources
Severity
7.8HIGHNVD
EPSS
1.7%
top 17.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMay 2

Description

Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

NVDcisco/ios12.1xu, 12.1yd, 12.2b+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xv9p-fx29-877q: Memory leak in the H2022-05-02
CVEList
CVE-2010-0583: Memory leak in the H2010-03-25

📋Vendor Advisories

1
Cisco
Cisco IOS Software H.323 Denial of Service Vulnerabilities2010-03-24
CVE-2010-0583 — Cisco IOS vulnerability | cvebase