SB2013110803 - Multiple vulnerabilities in Nextcloud ios



SB2013110803 - Multiple vulnerabilities in Nextcloud ios

Published: November 8, 2013 Updated: December 20, 2022

Security Bulletin ID SB2013110803
Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2012-3062)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.


2) Input validation error (CVE-ID: CVE-2012-4638)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.


3) Memory leak (CVE-ID: CVE-2012-0360)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376. A remote attacker can perform a denial of service attack.


4) Buffer overflow (CVE-ID: CVE-2012-1317)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.


5) Resource management error (CVE-ID: CVE-2013-5553)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.


Remediation

Install update from vendor's website.