You are here: hacking technology > crack analyzes > Content
Hot Articles
Recommend Articles
New Articles
Cisco SCCP and SIP agreement many long-distance security cracks
  Add date: 08/19/2008   Publishing date: 08/19/2008   Hits: 2
Total 2 pages, Current page:1, Jump to page:
 
Cisco SCCP and the SIP agreement saves mostly the long-distance security crack, below to everybody introduced that these cracks and give the solution.

  * DNS response analysis overflow

  Moves SCCP and SIP firmware's Cisco Unified IP Phone 7940, 7940G, 7960 and the 7960G equipment when processes the DNS response has the buffer overflow crack, the specially made DNS response may trigger the buffer overflow, in has on crack's telephone to carry out the random order. This crack record is CVE-2008-0530 and Cisco Bug ID CSCsj74818 and CSCsk21863.

  * ultra big ICMP returns obviously requested that refuses to serve

  Moves SCCP firmware's Cisco Unified IP Phone 7940, 7940G, 7960 and the 7960G equipment existence refuses to serve the crack, the long-distance aggressor may through transmit ultra big ICMP to return to obviously the request message to cause to have crack's equipment to restart. This crack record is CVE-2008-0526 and Cisco Bug ID CSCsh71110.

  * the HTTP server refuses to serve

  Moves SCCP firmware's Cisco Unified IP Phone 7935 and in 7936 equipment's internal HTTP server existences refuses to serve the crack. If to had the crack telephone's TCP 80 ports to transmit specially made HTTP to request, will cause the telephone to restart. The internal HTTP server only monitors in the TCP 80 ports. This crack record is CVE-2008-0527 and Cisco Bug ID CSCsk20026.

  * SIP MIME boundary overflow

  Moves SIP firmware's Cisco Unified IP Phone 7940, 7940G, 7960 and the 7960G equipment when processes the multipurpose Internet mail expands the (MIME) code the data has the buffer overflow crack. If to had crack's telephone transmission handtailor SIP news, triggered the buffer overflow on the possibility, carried out the random code on the telephone. This crack record is CVE-2008-0528 and Cisco Bug ID CSCsj74786.

  * the Telnet server overflows

  Moves SIP firmware's Cisco Unified IP Phone 7940, 7940G, 7960 and 7960G equipment's internal telnet server existence buffer overflow crack. the telnet server default is forbid, may dispose for the permission privilege or the non-privilege user level visit. If has begun using the telnet server visit to the privilege or non-privilege, then must the extra disposition telephone password parameter permit the telnet visit. If in disposition to allow the non-privilege visit on the telephone to input specially made order, might trigger the buffer overflow through the authentication non-privilege user, obtained visit to telephone's privilege. This crack record is CVE-2008-0529 and Cisco Bug ID CSCsj78359.

  * the SIP proxy responds the overflow

  Moves SIP firmware's Cisco Unified IP Phone 7940, 7940G, 7960 and the 7960G equipment when processing from the SIP proxy challenge/response news exists piles the overflow crack. If the aggressor controlled had SIP proxy which the crack telephone registered or attempts to register, or the aggressor might act is an intermediate, might and carries out the random order to the telephone transmission evil intention challenge/response news. This crack record is CVE-2008-0531 and Cisco Bug ID CSCsj74765.

 
Other pages: : 1 * 2 * Next>>
Prev:New cloud CMS the Online.asp page filtration is lax causes SQL to pour into the crack Next:BBSXP bypasses the filtration to continue to pour into the crack to analyze

Comment:

Category: Home > crack analyzes