Saturday, March 28, 2009

How Do You Change A Padlock Combination

Cisco IOS 12.x fixes 10 vulnerabilities in its March update cycle

Cisco has published, as every last Wednesday of March, eight security bulletins that address 10 vulnerabilities in its Cisco IOS operating system, which could be exploited by attackers to cause a denial of service or privilege escalation.

Briefly, the vulnerabilities are:

* It has been found that a sequence of TCP packets could cause a denial of service on Cisco IOS devices that are configured as an Easy VPN Server using Cisco Tunneling Control Protocol (CTCP .) It recommends applying the patches available or use IPSec NAT-T as an alternative.

The vulnerability is documented in the Cisco bug ID CSCsr16693 and CSCsu21828:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsr16693
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails. do? method = fetchBugDetails & BUGID = CSCsu21828

* vulnerability exists when handling IP sockets could be exploited by an attacker to cause denial of service, through a sequence of TCP / IP packets specially crafted, when enabled certain property Cisco IOS.

The vulnerability is documented in Cisco bug ID CSCsm27071:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm27071

* A vulnerability has been found on systems configured for Cisco IOS Mobile IP Network Address Translation (NAT) Traversal or Mobile IPv6 that could be exploited to cause a denial of service, causing the system interface process traffic ceases.

The vulnerability is documented in Cisco bug ID CSCsm97220 and CSCso05337:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm97220
http://tools.cisco .com / Support / BugToolKit / search / getBugDetails.do? method = fetchBugDetails & BUGID = CSCso05337

* There is a server-side failure in the implementation Secure Copy (SCP) in Cisco IOS could be exploited by an authenticated user with command line interface (CLI) to gain escalated privileges. The user can transfer files to or from, the device that is configured as a SCP. This could be exploited to access and write to any file on the device, can gain total control over it.

The vulnerability is documented in Cisco bug ID CSCsv38166:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsv38166

* We have found a vulnerability in Cisco IOS in the implementation of Session Initiation Protocol (SIP) which could be exploited by remote attackers to force a reboot of the device.

The vulnerability is documented in Cisco bug ID CSCsu11522:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsu11522

* found that multiple features Cisco IOS could allow a remote attacker to cause a denial of service on the affected system via a sequence of specially crafted TCP packets.

The vulnerability is documented in Cisco bug ID CSCsr29468:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsr29468

* We found a vulnerability when processing specially crafted UDP packets that would affect other property of Cisco IOS. If any of the affected is enabled, and specially crafted UDP packets sent to the affected device, it could stop processing traffic through the interface.

The vulnerability is documented in Cisco bug ID CSCsk64158:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsk64158

* found two vulnerabilities in Cisco IOS WebVPN or SSLVPN that could be exploited by an unauthenticated remote attacker to cause a denial of service on the device.

The first failure would occur when receiving specially crafted HTTPS packets and is documented in Cisco bug ID CSCsk62253:
http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsk62253

The second problem is caused by a memory leak in the device when processing SSL sessions that have been disrupted unexpectedly. The issue is documented in Cisco bug ID CSCsw24700:
http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsw24700


More Information:
Summary of Cisco
Bundled Software IOS Advisories, March 25, 2009
http://www.cisco.com/warp/public/707/cisco-sa-20090325-bundle.shtml

Source: http://www.hispasec.com/unaaldia/3807

Tuesday, March 17, 2009

Free Rick Solomon One Night In Paris

Privilege escalation in Cisco Unified Communications Manager

Cisco has released an update to Cisco Unified Communications Manager (versions 4.x, 5.x, 6.x and 7.x) that corrects a vulnerability in the synchronization feature of IP Phone Personal Address Book (PAB) that could allow a remote attacker to gain escalated privileges, which could lead to compromise vulnerable systems.

The Cisco Unified Communications solution is a set of products and communications applications
that collects and integrates voice, video and data.

The ruling could be exploited if an attacker intercepts the client credentials sent from Cisco Unified Communications Manager after you have authenticated to the synchronization process.

Cisco, through the usual channels, has made available to customers
solutions to solve the problem.

is advised to consult the table of vulnerable versions and countermeasures
:
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml

More Information:

Cisco Security Advisory: Cisco Unified Communications Manager IP Phone Address Book Synchronizer Personal Privilege Escalation Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml

Source: www.hispasec.com/unaaldia/ 3794 VoIP2DAY

Monday, March 2, 2009

Brampton Corelle Dinnerware Sale

VoIP2DAY! Videos superchulos

Welcome !!!!!!
Here is a link to some videos superchulisimos speaking, as you can imagine on VoIP. I hope you find it useful. Greetings.

VoIP2DAY What is?

VoIP2DAY born as a meeting place in the world of Voice and Video over IP in Spain and Portugal. Large fairs CeBIT generalists SIMO or have been weakened, and the really interesting thing in this day run are highly specialized fairs like the one in question.

The event is designed with the aspiration to establish itself as a benchmark annual boost for the growing local market and pointer to global technological level. That is why the participation of visitors is fundamental and most important of all, that your experience is valued as enriching post to mark your calendar and next year.

From the experience gained over the years as participants VoIP fairs in Europe and America, the organization has tried to pick the best of them and correct some of its shortcomings, the following are key to this new forum:

+ Fair for Professionals Only on weekdays
+ Free to attendees after registration required
Three Day Tours + + Exhibition Area
Manufacturers, Distributors and Integrators Conference
+ Zone 2 days tácnico orientation commercial and business cases and 1 day Axiter purely technical and community development of communication systems based on Free Software
+ Discussion Board on the day of the Open Source Community Days
+ Topics for days to focus the interest of visitors and exhibitors
+ Match in space and time during the trading days with the fair and complementary salon Call Center