First published: Thu Aug 26 2010(Updated: )
SIPD in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) allows remote attackers to cause a denial of service (stack memory corruption and process failure) via a malformed SIP message, aka Bug ID CSCtd14474.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Presence | =6.0 | |
Cisco Unified Presence | =6.0\(2\) | |
Cisco Unified Presence | =6.0\(3\) | |
Cisco Unified Presence | =6.0\(4\) | |
Cisco Unified Presence | =6.0\(5\) | |
Cisco Unified Presence | =6.0\(6\) | |
Cisco Unified Presence | =7.0 | |
Cisco Unified Presence | =7.0\(2\) | |
Cisco Unified Presence | =7.0\(3\) | |
Cisco Unified Presence | =7.0\(4\) | |
Cisco Unified Presence | =7.0\(5\) | |
Cisco Unified Presence | =7.0\(6\) | |
Cisco Unified Presence | =7.0\(7\) | |
Cisco Unified Presence | =6.0\(2.1101\) | |
Cisco Unified Presence | =6.0\(3.1101-2\) | |
Cisco Unified Presence | =6.0\(4.1101-5\) | |
Cisco Unified Presence | =6.0\(5.1101-1\) | |
Cisco Unified Presence | =6.0\(5.1103-2\) | |
Cisco Unified Presence | =6.0.5.1102-1 | |
Cisco Unified Presence | =7.0.3.10102-3 | |
Cisco Unified Presence | =7.0.3.10103-2 | |
Cisco Unified Presence | =7.0.4.10101-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-2839 is considered high due to its ability to cause remote denial of service.
To fix CVE-2010-2839, update Cisco Unified Presence to version 6.0(7) or 7.0(8) or later.
CVE-2010-2839 affects Cisco Unified Presence versions 6.x before 6.0(7) and 7.x before 7.0(8).
CVE-2010-2839 can be exploited through a malformed SIP message that leads to stack memory corruption.
There are no known workarounds for CVE-2010-2839; upgrading to a patched version is the recommended solution.