New User, Welcome!     Login

Media Gateway Control Protocol

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module

  * Domain Name System (DNS)
  * Session Initiation Protocol (SIP)
  * Simple Network Management Protocol (SNMP)
  * GPRS Tunneling Protocol (GTP)
  * H.323, H.225 RAS
  * Media Gateway Control Protocol (MGCP)
  * SunRPC
  * Trivial File Transfer Protocol (TFTP)
  * X Display Manager Control Protocol (XDMCP)
  * IBM NetBios
  * Instant Messaging (depending on the particular IM client/solution

Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and ASA Appliances

Two crafted packet vulnerabilities exist in the Cisco PIX 500 Series
Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security
Appliance (ASA) that may result in a reload of the device. These
vulnerabilities are triggered during processing of Media Gateway
Control Protocol (MGCP) packets, or during processing of Transport
Layer Security (TLS) traffic that terminates on the PIX or ASA security
appliance.

Note: These vulnerabilities are independent of each other; a device may
be affected by one and not by the other.

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

     no transport udp
     no transport tcp
     no transport tcp tls

warning Warning: When applying this workaround to devices that are
processing Media Gateway Control Protocol (MGCP) or H.323 calls, the
device will not stop SIP processing while active calls are being
processed. Under these circumstances, this workaround should be
implemented during a maintenance window when active calls can be
briefly stopped.


Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

     no transport udp
     no transport tcp
     no transport tcp tls

Warning: When applying this workaround to devices that are processing
Media Gateway Control Protocol (MGCP) or H.323 calls, the device will
not stop SIP processing while active calls are being processed. Under
these circumstances, this workaround should be implemented during a
maintenance window when active calls can be briefly stopped.

The "show udp connections", "show tcp brief all", and "show processes |

Cisco Security Advisory: Multiple Vulnerabilities in Firewall Services Module

=======

Two crafted packet vulnerabilities exist in the Cisco Firewall
Services Module (FWSM) that may result in a reload of the FWSM. These
vulnerabilities can be triggered during the processing of HTTPS
requests, or during the processing of Media Gateway Control Protocol
(MGCP) packets.

A third vulnerability may cause access control list (ACL) entries to not
be evaluated after the access list has been manipulated.


Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability

     no transport udp
     no transport tcp
     no transport tcp tls

Warning: When applying this workaround to devices that are
processing Media Gateway Control Protocol (MGCP) or H.323 calls, the
device will not stop SIP processing while active calls are being
processed. Under these circumstances, this workaround should be
implemented during a maintenance window when active calls can be
briefly stopped.


Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

     no transport udp
     no transport tcp
     no transport tcp tls

Warning: When applying this workaround to devices that are
processing Media Gateway Control Protocol (MGCP) or H.323 calls, the
device will not stop SIP processing while active calls are being
processed. Under these circumstances, this workaround should be
implemented during a maintenance window when active calls can be
briefly stopped.


Cisco Security Advisory: Multiple vulnerabilities in Cisco PGW Softswitch

=======

Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch
series of products. Each vulnerability described in this advisory is
independent from other. The vulnerabilities are related to processing
Session Initiation Protocol (SIP) or Media Gateway Control Protocol
(MGCP) messages.

Successful exploitation of all but one of these vulnerabilities can
crash the affected device. Exploitation of the remaining
vulnerability will not crash the affected device, but it can lead to

Cisco Security Advisory: Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers

    Domain Name System (DNS) server - port 53
    Resource Reservation Protocol (RSVP) - port 1698
    Layer Two Forwarding (L2F)/Layer Two Tunnel Protocol (L2TP) -
    port 1701
    IP SLA Responder - port 1967
    Media Gateway Control Protocol (MGCP) - port 2427
    Session Initiation Protocol (SIP) - port 5060

No other IPv4 UDP-based services are known to be affected.

How To Verify If IPv6 Is Enabled



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!