PT-2005-5457 · Cisco · Cisco Unity Express+6

Published

2005-12-31

·

Updated

2017-07-20

·

CVE-2005-4794

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IP Phones 7902/7912 versions not specified Cisco IP Phones 7905 versions not specified Cisco ATA 186 versions not specified Cisco ATA 188 versions not specified Cisco Unity Express versions not specified Cisco ACNS versions not specified Cisco Subscriber Edge Services Manager (SESM) versions not specified
Description The issue allows remote attackers to cause a denial of service, resulting in a crash or instability, by sending a compressed DNS packet with a label length byte that has an incorrect offset.
Recommendations For Cisco IP Phones 7902/7912, update to a version that fixes the issue with compressed DNS packets. For Cisco IP Phones 7905, update to a version that fixes the issue with compressed DNS packets. For Cisco ATA 186, update to a version that fixes the issue with compressed DNS packets. For Cisco ATA 188, update to a version that fixes the issue with compressed DNS packets. For Cisco Unity Express, update to a version that fixes the issue with compressed DNS packets. For Cisco ACNS, update to a version that fixes the issue with compressed DNS packets. For Cisco Subscriber Edge Services Manager (SESM), update to a version that fixes the issue with compressed DNS packets.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4794

Affected Products

Cisco Acns
Cisco Ata 186
Cisco Ata 188
Cisco Ip Phones 7902/7912
Cisco Ip Phones 7905
Cisco Subscriber Edge Services Manager
Cisco Unity Express