[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-4291Date: (C)2007-08-09   (M)2023-12-22


Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474; and a malformed Real-time Transport Protocol (RTP) packet, which causes a device crash, as identified by (4) CSCse68138, related to VOIP RTP Lib, and (5) CSCse05642, related to I/O memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.1
Exploit Score: 8.6
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
SECTRACK-1018533
http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtml
BID-25239
SECUNIA-26363
OSVDB-36677
OSVDB-36678
OSVDB-36679
OSVDB-36680
OSVDB-36681
ADV-2007-2816
cisco-ios-h323-dos(35904)
cisco-ios-mgcp-dos(35903)
cisco-ios-rtp-dos(35905)
oval:org.mitre.oval:def:5570

CPE    5
cpe:/o:cisco:ios:12.3
cpe:/o:cisco:ios:12.4
cpe:/o:cisco:ios:12.1
cpe:/o:cisco:ios:12.2
...

© SecPod Technologies