First published: Thu May 03 2012(Updated: )
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.1 | |
Cisco IOS | =15.0 | |
Cisco IOS | =12.4 | |
Cisco IOS | =15.2 | |
Cisco Unified Communications Manager | =7.1\(2b\)su1 | |
Cisco Unified Communications Manager | =7.1\(2b\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su4 | |
Cisco Unified Communications Manager | =7.1\(3b\) | |
Cisco Unified Communications Manager | =7.1 | |
Cisco Unified Communications Manager | =7.1\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1a | |
Cisco Unified Communications Manager | =7.1\(5b\)su1 | |
Cisco Unified Communications Manager | =7.1\(5b\)su3 | |
Cisco Unified Communications Manager | =7.1\(3\) | |
Cisco Unified Communications Manager | =7.1\(2a\) | |
Cisco Unified Communications Manager | =7.1\(5b\) | |
Cisco Unified Communications Manager | =7.0\(2a\) | |
Cisco Unified Communications Manager | =7.0\(1\)su1 | |
Cisco Unified Communications Manager | =7.0\(1\)su1a | |
Cisco Unified Communications Manager | =7.0\(1\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5\) | |
Cisco Unified Communications Manager | =7.1\(5a\) | |
Cisco Unified Communications Manager | =7.0\(2a\)su2 | |
Cisco Unified Communications Manager | =7.1\(5b\)su1a | |
Cisco Unified Communications Manager | =7.1\(5\)su1a | |
Cisco Unified Communications Manager | =7.0_base | |
Cisco Unified Communications Manager | =7.1\(5\)su1 | |
Cisco Unified Communications Manager | =7.0 | |
Cisco Unified Communications Manager | =7.1\(3a\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su5 | |
Cisco Unified Communications Manager | =7.1_base | |
Cisco Unified Communications Manager | =7.0\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1 | |
Cisco Unified Communications Manager | =7.0\(2\) | |
Cisco Unified Communications Manager | =7.1\(3b\)su2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4019 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2011-4019, upgrade the affected Cisco IOS or Unified Communications Manager to a version that is not vulnerable.
CVE-2011-4019 affects Cisco IOS versions 12.4, 15.0, 15.1, and 15.2 as well as Cisco Unified Communications Manager 7.x.
CVE-2011-4019 allows remote attackers to craft responses to SIP SUBSCRIBE messages leading to memory consumption and potential service disruption.
There are no specific workarounds for CVE-2011-4019, and updating to a secure version is the recommended approach.