<?xml version="1.0" encoding="UTF-8"?>
<rss  version="2.0"> 
   <channel>
  <title>Cisco Security Responses</title>
  <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
  <description>Cisco Security Responses (the 40 most recent responses)</description>
  <language>en-us</language>
  <copyright>&#xA9; 1992-2009 Cisco Systems, Inc. All rights reserved.</copyright>
  <managingEditor>news-at-cisco-rss@cisco.com</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com</webMaster>
  <pubDate>Fri, 19 Jun 2009 12:32:58 PST</pubDate>
  <lastBuildDate>Fri, 19 Jun 2009 11:00:00 PST</lastBuildDate>
  <category>Security Responses</category>
  <generator>News@Cisco RSS Script</generator>
  <docs>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</docs>
  <ttl>60</ttl>
  <image>
    <title>News@Cisco</title>
    <url>http://newsroom.cisco.com/images/mobile_newsAtCisco.png</url>
    <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
    <width>107</width>
    <height>70</height>
  </image>
  <textInput>
    <title>Search Cisco</title>
    <description></description>
    <name>searchPhrase</name>
    <link>http://www.cisco.com/pcgi-bin/search/search.pl</link>
  </textInput>
  
     <item>
    <title>Cisco IOS Cross-Site Scripting Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.html</link>
    <description>Two separate Cisco IOS? Hypertext Transfer Protocol (HTTP) cross-site scripting (XSS) vulnerabilities have been reported to Cisco by two independent researchers.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Cross-Site+Scripting+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.html</guid>
    <pubDate>Fri, 19 Jun 2009 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IP Phone 7940/7960 SIP INVITE Denial of Service</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html</link>
    <description>This is Cisco PSIRT's response to the statements made by Radu State in his message titled: CISCO Phone 7940 DOS vulnerability posted on 2007 March 20 0630 UTC (GMT). The original email is available at:http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053070.html Cisco has confirmed the findings of the statements made. Cisco IP Phone 7940/7960 SIP firmware version 7.4(0) is vulnerable to the denial of service. Firmware version 8.6(0) is not vulnerable to this issue. The latest firmware images for Cisco IP 7940/7960 phones can be obtained here: http://www.cisco.com/cgi-bin/tablebuild.pl/sip-ip-phone7960 We would like to thank Radu State, Humberto J. Abdelnur and Olivier Festor of the Madynes research team at INRIA for reporting these issues to Cisco Systems. We greatly appreciate the opportunity to work with researchers on security vulnerabilities, and welcome the opportunity to review and assist in product reports.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IP+Phone+7940/7960+SIP+INVITE+Denial+of+Service" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html</guid>
    <pubDate>Thu, 11 Jun 2009 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified MeetingPlace Stored Cross-Site Scripting Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a7bc61.html</link>
    <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by the National Australia Bank Security Assurance team regarding a cross-site scripting vulnerability in Cisco Unified MeetingPlace Web Conferencing. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+Stored+Cross-Site+Scripting+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a7bc61.html</guid>
    <pubDate>Thu, 26 Feb 2009 09:20:00 PST</pubDate>
  </item>
  <item>
    <title>MD5 Hashes May Allow for Certificate Spoofing</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html</link>
    <description>This is the Cisco response to research done by Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, and Benne de Weger pertaining to MD5 collisions in certificates issued by vulnerable certificate authorities. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=MD5+Hashes+May+Allow+for+Certificate+Spoofing" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html</guid>
    <pubDate>Thu, 15 Jan 2009 07:50:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Response to TKIP Encryption Weakness</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a30036.html</link>
    <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Response+to+TKIP+Encryption+Weakness" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a30036.html</guid>
    <pubDate>Fri, 21 Nov 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco VLAN Trunking Protocol Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a231cf.html</link>
    <description>This is the Cisco response to research done by 'showrun.lee' pertaining to a crafted VTP packet denial of service vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+VLAN+Trunking+Protocol+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a231cf.html</guid>
    <pubDate>Wed, 19 Nov 2008 06:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Response to Outpost24 TCP State Table Manipulation Denial of Service Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html </link>
    <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Response+to+Outpost24+TCP+State+Table+Manipulation+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html </guid>
    <pubDate>Fri, 17 Oct 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>VoIPshield Reported Vulnerabilities in Cisco Unity Server</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.html</link>
    <description>This is the Cisco PSIRT response to the vulnerabilities in Cisco Unity by VoIPshield, in their recent advisories (VSRCS-2008-008 to VSRCS-2008-012). The original advisories are available at: www.voipshield.com .&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=VoIPshield+Reported+Vulnerabilities+in+Cisco+Unity+Server" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.html</guid>
    <pubDate>Wed, 08 Oct 2008 11:10:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Secure ACS Denial Of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00809f140b.html</link>
    <description>This is the Cisco PSIRT response to the statements made by Laurent Butti and Gabriel Campana of Orange Labs / France Telecom Group, in their advisory: "Cisco Secure ACS EAP Parsing Vulnerability". The original advisory is available at: http://www.securityfocus.com/archive/1/495937/30/0/threaded &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Secure+ACS+Denial+Of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00809f140b.html</guid>
    <pubDate>Wed, 03 Sep 2008 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Internet Key Exchange Resource Exhaustion Attack</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00806f33d4.html</link>
    <description>This is a Cisco PSIRT response to an advisory published by an unaffiliated third party, Roy Hills, of NTA Monitor Ltd posted as of July 26, 2006 at http://www.nta-monitor.com/posts/2006/07/cisco-concentrator-dos.html, and entitled: Cisco VPN Concentrator IKE resource exhaustion DoS.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Internet+Key+Exchange+Resource+Exhaustion+Attack" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00806f33d4.html</guid>
    <pubDate>Mon, 28 Jul 2008 10:00:00 PST</pubDate>
  </item>
  <item>
    <title>Vulnerability in Java Secure Socket Extension</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008088bd19.html</link>
    <description>This is the Cisco PSIRT response to the vulnerability in Java Secure Socket Extension (JSSE) disclosed by Sun Microsystems on July 10, 2007, the details of which are available at http://sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Vulnerability+in+Java+Secure+Socket+Extension" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008088bd19.html</guid>
    <pubDate>Mon, 30 Jun 2008 10:30:00 PST</pubDate>
  </item>
  <item>
    <title>Wide Area Application Services (WAAS) Common UNIX Printing System (CUPS) Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.html</link>
    <description>This is the Cisco PSIRT response to a security advisory regarding a vulnerability in Common UNIX Printing System (CUPS). The CUPS security advisory can be found at http://www.cups.org/str.php?L2561.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Wide+Area+Application+Services+(WAAS)+Common+UNIX+Printing+System+(CUPS)+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.html</guid>
    <pubDate>Wed, 25 Jun 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Rootkits on Cisco IOS Devices</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080997783.html</link>
    <description>This is the Cisco PSIRT response to an issue that will be disclosed at the EUSecWest security conference on May 22nd, 2008 by Mr. Sebastian Muniz of Core Security Technologies. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Rootkits+on+Cisco+IOS+Devices" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080997783.html</guid>
    <pubDate>Mon, 23 Jun 2008 14:00:00 PST</pubDate>
  </item>
  <item>
    <title>Catalyst 6500 and Cisco 7600 Series Devices Accessible via Loopback Address</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808ca009.html </link>
    <description>This document is the Cisco PSIRT response to an issue regarding Cisco Catalyst 6500 and Cisco 7600 series devices that was discovered and reported to Cisco by Lee E. Rian .&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Catalyst+6500+and+Cisco+7600+Series+Devices+Accessible+via+Loopback+Address" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808ca009.html </guid>
    <pubDate>Wed, 20 Feb 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>CiscoWorks Server XSS Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008090a498.html</link>
    <description>This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by David Lewis of Liquidmatrix.org regarding a cross-site scripting (XSS) vulnerability in CiscoWorks Server login page.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=CiscoWorks+Server+XSS+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008090a498.html</guid>
    <pubDate>Wed, 05 Dec 2007 09:40:00 PST</pubDate>
  </item>
  <item>
    <title>Extensible Authentication Protocol Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808de8bb.html</link>
    <description>This is the Cisco PSIRT response to a presentation that was delivered by Laurent Butti, Julien Tinnhs and Franck Veysset of France Telecom Group at Hack.lu on October 19th, 2007.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Extensible+Authentication+Protocol+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808de8bb.html</guid>
    <pubDate>Sun, 02 Dec 2007 18:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified IP Phone Remote Eavesdropping</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html</link>
    <description>This is the Cisco PSIRT response to a presentation given at the Hack.Lu 2007 security conference by Joffery Czarny of Telindus regarding a technique to remotely eavesdrop using Cisco Unified IP Phones.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+IP+Phone+Remote+Eavesdropping" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html</guid>
    <pubDate>Fri, 30 Nov 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified MeetingPlace XSS Vulnerability (November 2007)</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808f0b8f.html</link>
    <description>This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by Joren McReynolds regarding a cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace Web Conferencing.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+XSS+Vulnerability+(November+2007)" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808f0b8f.html</guid>
    <pubDate>Wed, 07 Nov 2007 04:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Line Printer Daemon (LPD) Protocol Stack Overflow</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.html</link>
    <description>This is the Cisco Product Security Incident Response Team (PSIRT) response to an issue discovered and reported to Cisco by Andy Davis from IRM, Plc. regarding a stack overflow in the Cisco IOS Line Printer Daemon (LPD) Protocol feature. The original post is available at the following link:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Line+Printer+Daemon+(LPD)+Protocol+Stack+Overflow" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.html</guid>
    <pubDate>Wed, 10 Oct 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Reload on Regular Expression Processing</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html</link>
    <description>This is the Cisco Product Security Incident Response Team (PSIRT) response to a vulnerability that was reported on the Cisco NSP mailing list on August 17, 2007 regarding the crash and reload of devices running Cisco IOS. after executing a command that uses, either directly or indirectly, a regular expression.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Reload+on+Regular+Expression+Processing" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html</guid>
    <pubDate>Wed, 19 Sep 2007 09:00:00 PST</pubDate>
  </item>
  <item>
    <title>VTY Authentication Bypass Vulnerability</title>
    <link>http://www.cisco.com/warp/customer/707/cisco-sr-20070829-vty.shtml</link>
    <description>This is the Cisco PSIRT response to the NileSOFT Security Advisory 	 entitled "Bypass Authentication Vulnerability on Cisco Catalyst 3750 12.2(25)" posted on August 29th, 2007, at 1800 UTC (GMT).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=VTY+Authentication+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/warp/customer/707/cisco-sr-20070829-vty.shtml</guid>
    <pubDate>Fri, 07 Sep 2007 08:30:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple SIP Vulnerabilities in the Cisco 7960 IP Phones</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808a6693.html</link>
    <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Radu State, Humberto J. Abdelnur and Oliver Festor regarding two Session Initiation Protocol (SIP) vulnerabilities in the Cisco 7940/7960 IP Phones. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Multiple+SIP+Vulnerabilities+in+the+Cisco+7960+IP+Phones" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808a6693.html</guid>
    <pubDate>Wed, 22 Aug 2007 05:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified MeetingPlace XSS Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html</link>
    <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Roger Jefferiss and Rob Pope of SecureTest Ltd, UK regarding cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace Web Conferencing.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+XSS+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html</guid>
    <pubDate>Wed, 15 Aug 2007 06:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in OpenSSL Library</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008077af1b.html</link>
    <description>This is the Cisco PSIRT response to the multiple security advisories published by The OpenSSL Project. The vulnerabilities are as follows: RSA Signature Forgery (CVE-2006-4339), described in http://www.openssl.org/news/secadv_20060905.txt ASN.1 Denial of Service Attacks (CVE-2006-2937, CVE-2006-2940), described in http://www.openssl.org/news/secadv_20060928.txt SSL_get_shared_ciphers() buffer overflow (CVE-2006-3738), also in http://www.openssl.org/news/secadv_20060928.txt SSLv2 Client Crash (CVE-2006-4343), also in http://www.openssl.org/news/secadv_20060928.txt&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Multiple+Vulnerabilities+in+OpenSSL+Library" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008077af1b.html</guid>
    <pubDate>Wed, 25 Jul 2007 04:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html</link>
    <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Adam Blake of Deloitte, UK regarding a vulnerability in Cisco Trust Agent (CTA) installations on Mac OS X. The original report is available at the following link: http://www.securityfocus.com/archive/1/471041/30/0/flat.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Trust+Agent+-+Mac+OS+X+Privilege+Escalation+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html</guid>
    <pubDate>Tue, 12 Jun 2007 05:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco CallManager Input Validation Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080849272.html</link>
    <description>This is Cisco PSIRT's response to the statements made by Marc Ruef and Stefan Friedi from scip AG in their message "Cisco CallManager 4.1 Input Validation Vulnerability," posted on 2007 May 23 at 1600 UTC (GMT).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+CallManager+Input+Validation+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080849272.html</guid>
    <pubDate>Wed, 23 May 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>HTTP Full-Width and Half-Width Unicode Encoding Evasion</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008083f82e.html</link>
    <description>The U.S. Computer Emergency Response Team (US-CERT) has reported a network evasion technique using full-width and half-width unicode characters that affects several Cisco products. The US-CERT advisory is available at the following link: http://www.kb.cert.org/vuls/id/739224 &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=HTTP+Full-Width+and+Half-Width+Unicode+Encoding+Evasion" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008083f82e.html</guid>
    <pubDate>Fri, 18 May 2007 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>DHCP Relay Agent Vulnerability in Cisco PIX and ASA Appliances</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080833172.html</link>
    <description>This is a Cisco response to a CERT/CC advisory posted on May 2, 2007, entitled "Cisco ASA fails to properly process DHCP relay packets". &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=DHCP+Relay+Agent+Vulnerability+in+Cisco+PIX+and+ASA+Appliances" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080833172.html</guid>
    <pubDate>Wed, 02 May 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>PHP HTML Entity Encoder Heap Overflow Vulnerability in Multiple Web-Based Management Interfaces</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.html</link>
    <description>This is a response to a Hardened-PHP Project advisory posted on November 3, 2006, entitled "PHP HTML Entity Encoder Heap Overflow Vulnerability."&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=PHP+HTML+Entity+Encoder+Heap+Overflow+Vulnerability+in+Multiple+Web-Based+Management+Interfaces" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.html</guid>
    <pubDate>Wed, 25 Apr 2007 07:20:00 PST</pubDate>
  </item>
  <item>
    <title>Cross-Site Scripting Vulnerability in Online Help System</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html</link>
    <description>A cross-site scripting (XSS) vulnerability in the online help system distributed with several Cisco products has been independently reported to Cisco by Erwin Paternotte from Fox-IT and by Cassio Goldschmidt. The vulnerability would allow an attacker to execute arbitrary scripting code in a user's web browser if the attacker is successful in enticing the user to follow a specially crafted, malicious URL.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cross-Site+Scripting+Vulnerability+in+Online+Help+System" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html</guid>
    <pubDate>Wed, 11 Apr 2007 05:30:00 PST</pubDate>
  </item>
  <item>
    <title>NACATTACK Presentation</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html</link>
    <description>This is Cisco PSIRT's response to the "NACATTACK" presentation by Dror-John Roecher and Michael Thumann, presented at Blackhat Europe on March 30th, 2007.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=NACATTACK+Presentation" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html</guid>
    <pubDate>Fri, 30 Mar 2007 05:10:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco VTP Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00807d1a81.html</link>
    <description>An issue has been reported to the Cisco PSIRT involving malformed VLAN Trunking Protocol (VTP) packets. This attack may cause the target device to reload, causing a Denial of Service (DoS).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+VTP+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00807d1a81.html</guid>
    <pubDate>Tue, 27 Mar 2007 16:00:00 PST</pubDate>
  </item>
  <item>
    <title>Potential Exploitation of Default Administrative Credentials</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00807e3946.html</link>
    <description>This is a response to a Symantec published research paper posted on their website at http://www.symantec.com/enterprise/security_response/weblog/2007/02/driveby_pharming_how_clicking_1.html and http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf, and entitled 'Drive-by Pharming'. In particular, this response focuses on the information in the Symantec paper, as relevant to certain of Cisco's non-consumer products. These products are specified in the 'Cisco Routers Impacted' section below. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Potential+Exploitation+of+Default+Administrative+Credentials" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00807e3946.html</guid>
    <pubDate>Thu, 15 Feb 2007 07:20:00 PST</pubDate>
  </item>
  <item>
    <title>RealVNC Remote Authentication Bypass Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00806c4c31.html </link>
    <description>This is Cisco PSIRT's response to the CERT advisory http://www.kb.cert.org/vuls/id/117929  and acknowledged by Real VNC at http://www.realvnc.com/products/free/4.1/release-notes.html . This vulnerability was originally discovered by James Evans.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=RealVNC+Remote+Authentication+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00806c4c31.html </guid>
    <pubDate>Wed, 11 Oct 2006 10:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco VLAN Trunking Protocol Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00807335bc.html</link>
    <description>This is a Cisco response to an advisory published by FX of Phenoelit posted as of September 13, 2006, at http://www.securityfocus.com/archive/1/445896/30/0/threaded and entitled "Cisco Systems IOS VTP multiple vulnerabilities".&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+VLAN+Trunking+Protocol+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00807335bc.html</guid>
    <pubDate>Wed, 13 Sep 2006 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS GRE Decapsulation Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008072cd7b.html</link>
    <description>This is a Cisco response to an advisory published by FX of Phenoelit posted as of September 06, 2006, at http://www.securityfocus.com/archive/1/445322/30/0/threaded, and entitled "Cisco Systems IOS GRE decapsulation fault". &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+GRE+Decapsulation+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008072cd7b.html</guid>
    <pubDate>Wed, 06 Sep 2006 14:00:00 PST</pubDate>
  </item>
  <item>
    <title>NAC Agent Installation Bypass</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008071d609.html</link>
    <description>This is the Cisco PSIRT response to the statements made by Andreas Gal and Joachim Feise in their advisory entitled "NAC agent installation bypass", available at http://www.securityfocus.com/archive/1/444424/30/0/threaded We greatly appreciate the opportunity to work with researchers on security vulnerabilities, and welcome the opportunity to review and assist in product reports.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=NAC+Agent+Installation+Bypass" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008071d609.html</guid>
    <pubDate>Sat, 26 Aug 2006 10:00:00 PST</pubDate>
  </item>
  <item>
    <title>Mitigating Exploitation of the MS06-040 Service Buffer Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/ps6120/tsd_products_security_response09186a008070c75a.html</link>
    <description>This document contains information to assist Cisco customers in mitigating attempts to exploit the Microsoft Server Service Buffer Overflow Vulnerability. There is a remote code execution vulnerability in Server Service that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Mitigating+Exploitation+of+the+MS06-040+Service+Buffer+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/ps6120/tsd_products_security_response09186a008070c75a.html</guid>
    <pubDate>Mon, 21 Aug 2006 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>Unconfirmed SIP Inspection Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a008070d33b.html</link>
    <description>This is the initial response from the Cisco Product Security Incident Response Team (PSIRT) in regards to a potential vulnerability originally disclosed at the recent Black Hat USA 2006 Briefings. In a presentation entitled "SIP Stack Fingerprinting and Stack Difference Attacks", Hendrik Scholz referenced a potential vulnerability in the way the Cisco PIX 500 Series Security Appliances handle inspection of Session Initiation Protocol (SIP) messages.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Unconfirmed+SIP+Inspection+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a008070d33b.html</guid>
    <pubDate>Tue, 15 Aug 2006 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>SIP User Directory Information Disclosure</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a00806fc07e.html</link>
    <description>SIP User Directory Information Disclosure&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=SIP+User+Directory+Information+Disclosure" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a00806fc07e.html</guid>
    <pubDate>Wed, 02 Aug 2006 07:00:00 PST</pubDate>
  </item>
</channel>
   </rss>