Cisco released free software fixes for two sets of vulnerabilities that affect its Cisco Secure Access Control Server (ACS) for Windows User-Changeable Password (UCP) application. The flaws were reported to Cisco by Felix ‘FX’ Lindner of Recurity Labs.
The first flaw pinpoints several buffer overflow conditions in the UCP application that could result in remote execution of arbitrary code on the host system where UCP is installed, explains Cisco in its advisory. The second involves cross-site scripting in the UCP application pages. Hackers could exploit both sets of vulnerabilities without having to provide valid user credentials. Details of how to obtain the fixes are in the Cisco security advisory.
More Cisco Security Advisories here.
More Cisco Security Responses here.
More from Cisco Subnet: * Cisco, Patent Troll Tracker sued for defamation * Salary survey says CCIE pay is slipping * Understanding MPLS label distribution * Why an economic recession could leave companies wide open to cyber attacks * Cisco Ferrari or Nortel lawn mower, which one will customers choose to ride? * NX-OS’s best feature: Virtual Device Contexts * IBM to spend $1B prizing Cisco’s convergence customers away * Security wireless networks: Securing wireless comms over the air *20 useful sites for Cisco networking professionals Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more. Recent Cisconet blog entries Network World’s IT Buyer’s Guide: Cisco products




