19 Jan 2006
Cisco Systems has issued two patches for problems with its Call Manager VoIP software.
The first flaw was picked up by a customer and could have allowed hackers to launch a denial of service attack against the user's systems. All versions of Call Manager are vulnerable to the attack.
"Vulnerable versions of Call Manager do not manage TCP connections and Windows messages aggressively, leaving some well-known, published ports vulnerable to DoS attacks," stated the Cisco advisory.
"Call Manager does not time-out TCP connections to port 2000 aggressively enough, leading to a scenario where memory and CPU resources are consumed with enough open connections.
"In specific scenarios, Call Manager will leave the TCP connection open indefinitely until either the Call Manager service is restarted or the server is rebooted."
The second advisory covers a flaw that could allow a user with read-only access to gain full administrator privileges. This could be particularly serious if a hacker gained control of a computer and then used the flaw to obtain total access.
Cisco has made patches available on its website and is urging users to fix the flaws as soon as possible.
Latest stories from Communications
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
/ Corporate Account Manager / Management Consultant...
Prince 2 Project Management Professional, Client Facing...
Solution Architect / Technical Project Manager / Corporate...
Solution Architect / Technical Project Manager / Corporate...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?