2016 m. balandžio 13 d., trečiadienis

Cisco Security Advisory: Cisco TelePresence Server Crafted IPv6 Packet Handling Denial of Service Vulnerability

Cisco TelePresence Server Crafted IPv6 Packet Handling Denial of Service Vulnerability

Advisory ID:  cisco-sa-20160406-cts

Revision 1.0

For Public Release 2016 April 6 16:00 UTC (GMT)

+-----------------------------------------------------------
----------------------------

Summary
=======

A vulnerability in Cisco TelePresence Server devices running software versions 3.0
through 4.2(4.18) could allow an unauthenticated, remote attacker to cause a kernel
panic on the device.

The vulnerability exists due to a failure to properly handle a specially crafted stream
of IPv6 packets. A successful exploit could allow an attacker to cause a kernel panic,
rebooting the device.

Cisco has released software updates that address this vulnerability. Workarounds that
mitigate this vulnerability are available.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-cts

Komentarų nėra:

Rašyti komentarą