jim_duffy
Managing Editor

Cisco patches two flaws in its Secure Access Control Server

Analysis
Mar 12, 20082 mins

Cisco released free software fixes for two sets of vulnerabilities that affect its Cisco Secure Access Control Server (ACS) for Windows User-Changeable Password (UCP) application. The flaws were reported to Cisco by Felix ‘FX’ Lindner of Recurity Labs.

The first flaw pinpoints several buffer overflow conditions in the UCP application that could result in remote execution of arbitrary code on the host system where UCP is installed, explains Cisco in its advisory. The second involves cross-site scripting in the UCP application pages. Hackers could exploit both sets of vulnerabilities without having to provide valid user credentials. Details of how to obtain the fixes are in the Cisco security advisory.

More Cisco Security Advisories here.

More Cisco Security Responses here.

More from Cisco Subnet:

* Cisco, Patent Troll Tracker sued for defamation

* Salary survey says CCIE pay is slipping

* Understanding MPLS label distribution

* Why an economic recession could leave companies wide open to cyber attacks 

* Cisco Ferrari or Nortel lawn mower, which one will customers choose to ride?

* NX-OS’s best feature: Virtual Device Contexts

* IBM to spend $1B prizing Cisco’s convergence customers away

* Security wireless networks: Securing wireless comms over the air

* Building your CCNP lab

*20 useful sites for Cisco networking professionals

* March Giveaways: Win access to Tech 2000’s CCNA Lab Simulator; win a copy of Cisco Networking Simplified, 2nd Edition

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

Recent Cisconet blog entries

Network World’s IT Buyer’s Guide: Cisco products