>> Cisco Unified Presence Remote Denial of Service Vulnerabilities
Title : Cisco Unified Presence Remote Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1534 CVE ID : CVE-2008-1158 - CVE-2008-1740 - CVE-2008-1741
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-14
Technical Description
Multiple vulnerabilities have been identified in Cisco Unified Presence, which could be exploited by attackers to cause a denial of service.
The first issue is caused by errors in the Presence Engine service when handling a series of malformed IP packets, which could be exploited by attackers to create a denial of service condition.
The second vulnerability is caused by an error in the SIP Proxy service when handling a specially crafted TCP port scan, which could be exploited by attackers to create a denial of service condition.