CVE-2008-0530: Buffer Overflow
Published Feb 15, 2008
·Updated
Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.
Affected Software
14 affected components
Cisco Unified IP Phone=7906g
Cisco Unified IP Phone=7911g
Cisco Unified IP Phone=7935
Cisco Unified IP Phone=7936
Cisco Unified IP Phone=7940
Cisco Unified IP Phone=7940g
Cisco Unified IP Phone=7941g
Cisco Unified IP Phone=7960
Cisco Unified IP Phone=7960g
Cisco Unified IP Phone=7961g
Cisco Unified IP Phone=7970g
Cisco Unified IP Phone=7971g
Cisco Skinny Client Control Protocol \(sccp\) Firmware
Cisco Session Initiation Protocol \(sip\) Firmware
Remediation
Event History
Feb 15, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:00 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-0530?
CVE-2008-0530 has been classified with a high severity due to potential remote code execution.
2
How do I fix CVE-2008-0530?
To mitigate CVE-2008-0530, it is recommended to update the firmware of affected Cisco Unified IP Phones to the latest version provided by Cisco.
3
Which devices are affected by CVE-2008-0530?
CVE-2008-0530 affects Cisco Unified IP Phones 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware.
4
Can CVE-2008-0530 be exploited remotely?
Yes, CVE-2008-0530 can be exploited remotely through specially crafted DNS responses.
5
What are the consequences of a successful exploit of CVE-2008-0530?
Successful exploitation of CVE-2008-0530 may allow attackers to execute arbitrary code on the affected Cisco IP Phone.