CVE-2010-2839: High severity Cisco Unified Presence Server vulnerability
Published Aug 26, 2010
·Updated
SIPD in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) allows remote attackers to cause a denial of service (stack memory corruption and process failure) via a malformed SIP message, aka Bug ID CSCtd14474.
Affected Software
22 affected components
Cisco Unified Presence Server=6.0
Cisco Unified Presence Server=6.0\(2\)
Cisco Unified Presence Server=6.0\(3\)
Cisco Unified Presence Server=6.0\(4\)
Cisco Unified Presence Server=6.0\(5\)
Cisco Unified Presence Server=6.0\(6\)
Cisco Unified Presence Server=7.0
Cisco Unified Presence Server=7.0\(2\)
Cisco Unified Presence Server=7.0\(3\)
Cisco Unified Presence Server=7.0\(4\)
Cisco Unified Presence Server=7.0\(5\)
Cisco Unified Presence Server=7.0\(6\)
Cisco Unified Presence Server=7.0\(7\)
Cisco Unified Presence Server=6.0\(2.1101\)
Cisco Unified Presence Server=6.0\(3.1101-2\)
Cisco Unified Presence Server=6.0\(4.1101-5\)
Cisco Unified Presence Server=6.0\(5.1101-1\)
Cisco Unified Presence Server=6.0\(5.1103-2\)
Cisco Unified Presence Server=6.0.5.1102-1
Cisco Unified Presence Server=7.0.3.10102-3
Cisco Unified Presence Server=7.0.3.10103-2
Cisco Unified Presence Server=7.0.4.10101-2
Remediation
Event History
Aug 26, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2839?
The severity of CVE-2010-2839 is considered high due to its ability to cause remote denial of service.
2
How do I fix CVE-2010-2839?
To fix CVE-2010-2839, update Cisco Unified Presence to version 6.0(7) or 7.0(8) or later.
3
What products are affected by CVE-2010-2839?
CVE-2010-2839 affects Cisco Unified Presence versions 6.x before 6.0(7) and 7.x before 7.0(8).
4
What type of attack exploits CVE-2010-2839?
CVE-2010-2839 can be exploited through a malformed SIP message that leads to stack memory corruption.
5
Is there a known workaround for CVE-2010-2839?
There are no known workarounds for CVE-2010-2839; upgrading to a patched version is the recommended solution.