ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

NISCC warns on Cisco IP phone flaw

Marguerite Reardon CNET News.com

Published: 25 May 2005 10:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A software flaw that could crash Cisco's IP phones has been discovered, and the networking company has issued a patch to fix the problem.

The flaw, which opens the IP phone service up to DoS attacks, was reported by the National Infrastructure Security Co-ordination Centre, the Government's cybersecurity group, in its warning, it gave the DNS protocol vulnerability, which also affects other software, a "moderate risk" warning.

To expedite lookups on DNS servers, log files are often compressed. According to the advisory, the vulnerability is caused by an error that occurs during the decompression of compressed DNS messages. The flaw can be exploited using specially crafted DNS packets containing invalid information in the compressed section of the message. This results in an error in processing on the IP phones, which could cause the phones malfunction or crash.

In an advisory issued by Cisco, the company said the only products impacted are DNS clients, which run on its IP phones and content-networking products. The security flaw does not appear in products performing DNS server functions or DNS packet inspection. Affected products include Cisco IP Phones 7902/7905/7912; Cisco ATA (Analog Telephone Adaptor) 186/188; and several Cisco Unity Express and Cisco ACNS (Application and Content Networking System) devices.

Cisco has posted a complete list of affected products on its Web site. It said it has also developed a free software upgrade to fix the problem.

Other vendors also use the DNS protocol in their products, which also may be vulnerable, according to an advisory from the French Security Incident Response Team. Users should contact their vendors for more information about affected products and fixes, the group said.

CNET News.com's Joris Evers contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
80 out of 164 people found this useful


Full Talkback thread

0 comments


Related Jobs

Cisco & VOIP Engineer - 40,000 - Leeds

With an excellent working knowledge (at least 2years) of Cisco Phone Services and VOIP and experience supporting and administering call manager/call ...

Cisco VoIP / IPT Engineer - Oxfordshire

Cisco Call Manager and Cisco Voice Gateways are absolute must-haves while any of the following would be beneficial: Cisco Unity voicemail, IPCC ...

IP Engineer - Scotland Cisco Avaya IP

Working on there various sites you will be involved in the support and rollout of IP phones, both Avaya and Cisco. Gear Router/Switches Cisco Driving ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment