lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: Mon,  8 Sep 2014 12:09:37 -0400
From: Cisco Systems Product Security Incident Response Team <psirt@...co.com>
To: bugtraq@...urityfocus.com
Cc: psirt@...co.com
Subject: Cisco Security Advisory: Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability

Advisory ID: cisco-sa-20140908-ucse

Revision 1.0

For Public Release 2014 September 8 16:00  UTC (GMT)
+--------------------------------------------------------------------

Summary
=======

A vulnerability in the Cisco Integrated Management Controller (Cisco IMC) SSH module of the Cisco Unified Computing System E-Series Blade servers could allow an unauthenticated, remote attacker to cause a denial of service condition.

The vulnerability is due to a failure to properly handle a crafted SSH packet. An attacker could exploit this vulnerability by sending a crafted packet to the SSH server running on the Cisco IMC of an affected device, which could result in the Cisco IMC becoming unresponsive. The operating system running on the blade will be unaffected.

Cisco has released free software updates that address this vulnerability.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140908-ucse

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org

iQIcBAEBAgAGBQJUDccEAAoJEIpI1I6i1Mx380EQAJZ/vFS3FAVaZRj/ylDlZEoN
rTNQmIXP/8M+gXHUVZQPF5BKXeHOqdEyA+AKOhgttLpuYfIyi/7oYhU9vETWs1dh
4d8/6QG2+6ImYfig8KS8oartWgVyifq389PqprXK1QhuKhU30DgEAV+2nvTDe46n
5XAaQ2mbey47dmdfFkrLNIjpdkjyx07ibj7yaHwsQY0plDH3ldTEIV+Ca1AnA/Dj
J9ECXHnWVoqlS3WXPrXWeFLj9OJM+Htq84rYJb1Uc7EoxTUz8NwFmNUzY93esYBJ
gev4l6rQHy/m70fPdBXbfuSr4UwsQA4FYjfF60924IPZ63EYsnFICC14doci7CjT
JzZ3lyvnmFbiQ/OOdwRTsJjD0knGq5FBAF9WUFfZ3KVnXcq62ztMlCE2BscSZz0/
Yw0wnFrPwmz0VqXJxs+TUeDyq2w/cS8piWO5+XkYTc3dmmRNzf5N0tXE7vekWKhX
pmZfaoviY6LoJjzN8BsBTvJ8slAI8ldJ10cEVuuFB3CQSalYrspH8bKXAsu+5T6v
4CoQuwB7alb3l/RUqthpR9uakV6FLG2jVi4WkgcBaPrz7FLo+4k3z6WpLcUXBUpK
81zTK1c2iWhbPEil1zLEHaEwWm4hPp1qAeWEuQH4ahBLbl/pxwXD/xX3vZdDD7Ed
HvavuCQ1ZhZRr6nR+EUq
=Ydqd
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ