First published: Tue Jul 12 2005(Updated: )
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =4.1 | |
Cisco Unified Communications Manager | =3.2 | |
Cisco Unified Communications Manager | =3.3 | |
Cisco Unified Communications Manager | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2241 is rated as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2005-2241, upgrade to a version of Cisco CallManager that is not affected, such as 3.3(5) or later, 4.0(2a)SR2b or later, or 4.1(3)SR1 or later.
CVE-2005-2241 affects Cisco CallManager versions 3.2, 3.3, 4.0, and 4.1 before their respective patched versions.
CVE-2005-2241 can cause a memory leak that leads to a denial of service, making the service unavailable to users.
Yes, CVE-2005-2241 can be exploited by remote attackers due to the improper handling of Realtime Information Server Data Collection sockets.