
====================================================================

                              CERT-Renater

                 Note d'Information No. 2017/VULN024
_____________________________________________________________________

DATE                : 26/01/2017

HARDWARE PLATFORM(S): Cisco TelePresence Multipoint Control Unit.

OPERATING SYSTEM(S): Cisco TelePresence Multipoint Control Unit
                                   software.

=====================================================================
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-telepresence
____________________________________________________________________

Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit
Remote Code Execution Vulnerability

Advisory ID: cisco-sa-20170125-telepresence

Revision 1.0

For Public Release 2017 January 25 16:00  UTC (GMT)

+---------------------------------------------------------------------

Summary
=======

A vulnerability in a proprietary device driver in the kernel of Cisco
TelePresence Multipoint Control Unit (MCU) Software could allow an
unauthenticated, remote attacker to execute arbitrary code or cause a
denial of service (DoS) condition.

The vulnerability is due to improper size validation when reassembling
fragmented IPv4 or IPv6 packets. An attacker could exploit this
vulnerability by sending crafted IPv4 or IPv6 fragments to a port
receiving content in Passthrough content mode. An exploit could allow
the attacker to overflow a buffer. If successful, the attacker could
execute arbitrary code or cause a DoS condition on the affected system.

Cisco has released software updates that address this vulnerability.
Workarounds that address this vulnerability are not available.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-telepresence

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================



