First published: Fri May 16 2008(Updated: )
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CSCsh50164.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Presence Server | =1.0 | |
Cisco Unified Presence Server | =1.0\(1\) | |
Cisco Unified Presence | =6.0 | |
Cisco Unified Presence Server | =1.0\(3\) | |
Cisco Unified Presence Server | =1.0\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1158 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2008-1158, upgrade to the version of Cisco Unified Presence that is not vulnerable, specifically any version after 6.0(1).
CVE-2008-1158 affects various versions of Cisco Unified Presence Server, including 1.0, 1.0(1), 1.0(2), 1.0(3), and 6.0.
CVE-2008-1158 can be exploited via remote attacks that send malformed packets to the Presence Engine service.
The impact of CVE-2008-1158 includes service interruptions and core dumps, leading to denial of service.