New User, Welcome!     Login

voice/over/IP

Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, voice-over-IP gateways, and
multimedia applications.

SIP is a popular signaling protocol that is used to manage voice and

Cisco Security Advisory: Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities

addressed in this advisory.

There are no workarounds available to mitigate the effects of any of
the vulnerabilities apart from disabling the protocol or feature
itself, if administrators do not require the Cisco IOS device to
provide voice over IP services.

This advisory is posted at 
http://www.cisco.com/warp/public/707/cisco-sa-20080924-sip.shtml

Note:  The September 24, 2008 IOS Advisory bundled publication

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, voice-over-IP (VoIP) gateways,
and multimedia applications.

Certificate Trust List Provider Related Vulnerabilities

Cisco Security Advisory: SQL injection in Cisco Unified Communications Manager

Details
=======

Cisco Unified CallManager/Communications Manager (CUCM) is the call
processing component of the Cisco IP telephony solution. This
solution extends enterprise telephony features and functions to
packet telephony network devices such as IP phones, media processing
devices, voice-over-IP (VoIP) gateways, and multimedia applications.

An attacker can trigger this SQL injection vulnerability by entering

Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow

Details
=======

Cisco Unified Communications Manager (CUCM) is the call processing
component of the Cisco IP telephony solution that extends enterprise
telephony features and functions to packet telephony network devices,
such as IP phones, media processing devices, voice-over-IP (VoIP)
gateways, and multimedia applications.

When a CUCM server is deployed in secure mode, a Certificate Trust

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, voice-over-IP (VoIP) gateways,
and multimedia applications.

Certificate Trust List Provider Related Vulnerabilities

Cisco Security Advisory: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page

Details
=======

Cisco Unified CallManager/Communications Manager (CUCM) is the call
processing component of the Cisco IP telephony solution which extends
enterprise telephony features and functions to packet telephony network
devices such as IP phones, media processing devices, voice-over-IP
(VoIP) gateways, and multimedia applications.

The cross-site scripting vulnerability and the SQL injection

LayerOne 2008 Update

David 'Video Man' Bryan is computer security consultant for NetSPI and
a senior organizer of the annual DEFCON (www.defcon.org) computer
security conference in Las Vegas, NV. David will be presenting on the
potential threats and vulnerabilities surrounding Voice over IP
telephony. Topics covered will include voice privacy issues, quality
of service, and mitigating strategies for companies and individuals
looking to take advantage of this technology.

LayerOne is continuing to look for additional speakers for this year's
conference. If you are interested in speaking, please visit our site

Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, voice-over-IP gateways, and
multimedia applications.

SIP is a popular signaling protocol that manages voice and video

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, VoIP gateways, and multimedia
applications.

Malformed SIP Message Vulnerabilities

[scip_Advisory 4142] Skype Client for Mac Chat Unicode Denial of Service

scip AG Vulnerability ID 4142 (06/22/2010)
http://www.scip.ch/?vuldb.4142

I. INTRODUCTION

Skype is a very popular proprietary voice-over-ip client available for
multiple platforms.

More information is available on the official web site at the following URL:

http://www.skype.com

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Details
=======

Cisco Unified Communications Manager is the call processing component
of the Cisco IP Telephony solution that extends enterprise telephony
features and functions to packet telephony network devices, such as
IP phones, media processing devices, VoIP gateways, and multimedia
applications.

Malformed SCCP Message Vulnerabilities

CanSecWest 2008 Mar 26-28

Vulnerability Discovery Demystified             Mark Dowd and Justin Schuh
The Exploit Laboratory - Advanced Edition               Saumil Shah
Advanced Honeypot Tactics               Thorsten Holz
Mastering the network with Scapy                Philippe Biondi
Voice over IP (VoIP) Security           Nico Fischbach
Practical 802.11 WiFi (In)Security              Cdric Blancher
Advanced Linux Hardening                Andrea Barisani
Defend The Flag         Microsoft

--

[ GLSA 200904-13 ] Ventrilo: Denial of Service

of Service.

Background
==========

Ventrilo is a Voice over IP group communication server.

Affected packages
=================

    -------------------------------------------------------------------

CVE-2009-4510: TANDBERG VCS Static SSH Host Keys

- From [1]:

 "The Video Communication Server (VCS) is an integral part of the TANDBERG 
  Total Solution and is the center of the video communications network, 
  connecting the benefits of video conferencing and telepresence to other 
  communications environments including unified communications and IP Telephony
  networks."


Vulnerability Overview
- ----------------------

Cisco Security Advisory: Cisco Unified Communications Manager Express Vulnerability

Details
=======

Cisco Unified CME is the call processing component of an enhanced IP
telephony solution that is integrated into Cisco IOS.

The Extension Mobility feature in Cisco Unified CME provides the
benefit of phone mobility for end users. A user login service allows
phone users to temporarily access a physical phone other than their
own phone and utilize their personal settings, such as directory

SEC Consult SA-20090415-1 :: Nortel Application Gateway 2000 Password Disclosure Vulnerability

Vendor description:
-------------------

The Application Gateway delivers practical, converged voice and data
applications on Nortel IP phones that enable organizations to benefit
more fully from IP telephony. The prepackaged, easy-to-learn,
easy-to-use Voice Office applications help increase productivity and
enhance organizational communications - without requiring any
integration work. For the hospitality sector, the Guest Services
applications provide additional services/features, generate revenue from
advertising on the phone screen, and reduce the cost of operations by

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities

Details
=======

Cisco Unified Communications Manager (CUCM) is the call processing
component of the Cisco IP Telephony solution that extends enterprise
telephony features and functions to packet telephony network devices,
such as IP phones, media processing devices, VoIP gateways, and
multimedia applications.

Computer Telephony Integration Manager Related Vulnerability

CVE-2009-4511: TANDBERG VCS Arbitrary File Retrieval

- From [1]:

 "The Video Communication Server (VCS) is an integral part of the TANDBERG 
  Total Solution and is the center of the video communications network, 
  connecting the benefits of video conferencing and telepresence to other 
  communications environments including unified communications and IP Telephony
  networks."


Vulnerability Overview
- ----------------------

CVE-2009-4509: TANDBERG VCS Authentication Bypass

- From [1]:

 "The Video Communication Server (VCS) is an integral part of the TANDBERG 
  Total Solution and is the center of the video communications network, 
  connecting the benefits of video conferencing and telepresence to other 
  communications environments including unified communications and IP Telephony
  networks."


Vulnerability Overview
- ----------------------



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!