jim_duffy
Managing Editor

Cisco releases semiannual security advisories

Analysis
Mar 26, 20102 mins

11 vulnerabilities affecting 7 IOS features

Cisco this week published its semiannual IOS software security advisory, which actually includes seven advisories on 11 vulnerabilities. The vulnerabilities could result in remote code execution or a denial of service, Cisco says.

Cisco says it also issued software releases that correct all 11 vulnerabilities.

The vulnerabilities affect MPLS, IPSec, TCP, SIP, H.323, NAT “Skinny” call control protocol and Unified Communications Manager Express. SIP has three vulnerabilities affecting message handling and processing, and packet parsing; H.323 has two, including a blocked interface for packet processing and a memory leak; and Unified Communications Manager has two, affecting packet processing and request handling of the Skinny Client Control Protocol.

The highest rated vulnerabilities are the SIP message handling and packet parsing liabilities.

More from Cisco Subnet:

This is Network World’s Cisco Subnet news alert in which we focus on the top items from Cisco Subnet, your source for Cisco news, blogs, discussion items, security alerts, giveaways and more.

Cisco said to be readying major upgrade to CRS-1The scoop on the New TSHOOT Course and Exam

Cisco shipping 160G Ethernet card for ASR 9000

Another analyst sees Cisco UCS deployment delays

If Cisco buys you, you’re 1 in 100

IPv4 Space is Getting Low – Really Low

Win one of 50 CCNP training books, videos and Cert Kits

Win great stuff from Cisco SubnetCisco Alert newsletter.Like RSS readers? Subscribe to the Cisco Subnet RSS feed

Like e-mail? Subscribe to the

Follow all Cisco Subnet bloggers on Twitter.Follow Jim Duffy on Twitter