Cisco AsyncOS Denial of Service Vulnerability (CVE-2015-6291)
Cisco AsyncOS Denial of Service Vulnerability (CVE-2015-6291)
Release date:
Updated on:
Affected Systems:
Cisco AsyncOS <8.5.7-043
Cisco AsyncOS 9. x-9.1.1-023
Cisco AsyncOS 9.6.x-9.6.0-046
Cisco AsyncOS 9.5.x
Description:
CVE (CAN) ID: CVE-2015-6291
The Cisco AsyncOS operating system improves the security and performance of Cisco email security devices.
Cisco AsyncOS 8.5.7-043, 9. x-9.1.1-023, 9.5.x, 9.6.x-9.6.0-046, message filters configure multiple rules that will incorrectly handle malformed fields, which allows remote attackers to construct email attachments to consume memory, this causes a denial of service.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151104-esa2
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20151104-esa2) and patches for this:
Cisco-sa-20151104-esa2: Cisco Email Security Appliance Email protected Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151104-esa2
This article permanently updates the link address: