Buffer Overflow in Cisco ACS for Windows
Cisco Secure ACS for Windows contains a buffer overflow condition that can permit a Denial of Service (DoS) attack and a root compromise.
April 22, 2003
ReportedApril 23, 2003, by Cisco Systems
VERSIONSAFFECTED
CiscoSecure ACS 3.1.1, 3.0.3, 2.6.4, and earlier
DESCRIPTION
CiscoSecure ACS for Windows contains a buffer overflow condition that canpermit a Denial of Service (DoS) attack and a root compromise. Theproblem appears to occur during the software's handling of logonsequences.
Ciscorecommends that customers upgrade to repaired versions of CiscoSecure ACS or install Cisco Secure ACS so that either no externalaccess to management interfaces is permitted or access to theinterfaces is restricted. Users who want to restrict access tomanagement interfaces need to block access to ACS on port 2002.
VENDORRESPONSE
Ciscohas released a bulletinand free upgrades, which you can download from the company's Website.
CREDIT
Discovered byNSFocus.
About the Author
You May Also Like