99c.org
Cisco Plugs VoIP Gateway Holes
Posted on 07.15.05 by templeton @ 7:32 pm

Network equipment supplier Cisco has issued patches for several security flaws in its voice-over IP gateways that hackers could exploit and use to eavesdrop on telephone calls.

The vulnerability could also be exploited to issue denial-of-service attacks on services managed by its VoIP software platform.

The most recent VoIP security flaws, discovered by security unit Internet Security Systems(ISS) X-Force team, are located in Cisco’s Call Manager, an essential component to the functioning of any Cisco VoIP deployment that perform call signaling and call routing.

The vulnerabilities make it possible for an attacker to trigger a heap overflow within a critical Call Manager process, causing both a denial of service condition and enabling an attacker to completely compromise the Call Manager server, ISS said.

“Like many of the applications that are driving today’s businesses, VoIP travels over a variety of networks and the public Internet and is therefore susceptible to the same security perils as other staple network components like e-mail, databases and servers,” Chris Rouland, chief technology officer at ISS, said in a statement.

“We are aware of several vulnerabilities that potentially affect the Cisco Call Manager software. To date, Cisco is not aware of any active exploitation of these vulnerabilities and Cisco has made free software fix available,” the company said.

Cisco is not aware of any active exploitation of these vulnerabilities and Cisco has made free software fix available.

“An attacker may be able to redirect calls or perform eavesdropping as a result of this compromise. Successful exploitation of this vulnerability could be used to gain unauthorized access to networks and machines with Cisco VoIP products,” the company said.

No authentication is required for an attacker to exploit the vulnerability and compromise a network, according to ISS.

“Voice over Internet Protocol is increasingly being adopted by corporations that wish to save money on telecommunications costs and streamline their communication infrastructure, providing employees with advanced features while simplifying administration processes,” Rouland said.


Filed under: VOIP
Comments:

1 Comment »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>




Shorten URL




 Engadget

 Privacy


 Open Source


Recent Stories
» Apple cuts copy protection and prices on iTunes (AP)
» Apple disappoints: No Jobs or big news at Macworld (Reuters)
» Social Security unveils new online application (AP)
» Apple Unveils New MacBook Pro, Drops DRM for iTunes (NewsFactor)
» Apple disappoints--no Jobs or big news at Macworld (Reuters)
» Curl bolsters RIA data access (InfoWorld)
» Model wants Google to identify anonymous commenter (AP)
» Best Buy Offers Refurbished IPhones (PC World)
» Fake celeb LinkedIn profiles lead to malware (CNET)
» Truphone adds Skype, Twitter to iPhone client (CNET)
» Apple cuts copy protection and prices on iTunes (AP)
» Even in recession, CES to have stuff worth seeing (AP)
» Apple's Jobs has hormone imbalance, will stay CEO (AP)
» Logitech to cut salaried staff by 15 percent (AP)
» Fake celeb LinkedIn profiles lead to malware (CNET)