Cisco released a slew of security alerts over the past 2 days, including Wednesday, when Cisco.com suffered a near three-hour outage.
* Cisco warned that the Next Hop Resolution Protocol in IOS contains a vulnerability that can result in a restart of the device or possible remote code execution. More details.
* Cisco IOS and Cisco IOS XR contain a vulnerability when processing specially crafted IPv6 packets with a Type 0 Routing Header present. Fixes are available.
* The server side of the Secure Copy implementation in IOS could allow any valid user to transfer files to and from an IOS device that is configured to be a Secure Copy server. More details.
* IOS also has multiple voice-related vulnerabilities, one of which is also shared with Cisco Unified Communications Manager. The vulnerabilities pertain to the following: Session Initiation Protocol; Media Gateway Control Protocol; Fixes are available.
Signaling protocols H.323, H.254; Real-time Transport Protocol; and Facsimile reception.
Separately, Cisco issued a response to a cross-site scripting (XSS) hole in Cisco Unified MeetingPlace Web Conferencing, which was discovered by researchers at SecureTest in the United Kingdom. Cisco has no workaround for this vulnerability.
Go here for Cisco security alerts
Go here for Cisco security responses
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.




