ID

VAR-201101-0006


CVE

CVE-2009-5039


TITLE

Cisco IOS of H.323 Implementation gk_circuit_info_do_in_acf Service disruption in functions (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2011-001124

DESCRIPTION

Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535. Cisco IOS of H.323 Implementation gk_circuit_info_do_in_acf Function leaks memory and interferes with service operation (DoS) There is a vulnerability that becomes a condition. The problem is Bug ID CSCsz72535 It is a problem.Denial of service by a large number of long-term calls by third parties (DoS) There is a possibility of being put into a state. Cisco IOS is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause the affected device to consume an excessive amount of memory, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCsz72535. Cisco IOS is an operating system developed by Cisco in the United States for its network equipment

Trust: 1.98

sources: NVD: CVE-2009-5039 // JVNDB: JVNDB-2011-001124 // BID: 45758 // VULHUB: VHN-42485

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:ltversion:15.0\(1\)xa

Trust: 1.0

vendor:ciscomodel:iosscope:ltversion:15.0 (1)xa

Trust: 0.8

vendor:ciscomodel:iosscope:eqversion:12.4\(4\)mr

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.3yz

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4\(1b\)

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4\(3\)t2

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4ja

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4\(2\)xb2

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4\(3d\)

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.3yx

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.4

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.3yu

Trust: 0.6

vendor:ciscomodel:ios 15.0 xascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios mscope:eqversion:15.0

Trust: 0.3

vendor:ciscomodel:ios 15.0mscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.0 m1scope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.0 m2scope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.0sscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.0 m3scope: - version: -

Trust: 0.3

vendor:ciscomodel:ios m3scope:eqversion:15.0

Trust: 0.3

vendor:ciscomodel:ios 15.0xoscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.0xascope: - version: -

Trust: 0.3

sources: BID: 45758 // JVNDB: JVNDB-2011-001124 // CNNVD: CNNVD-201101-025 // NVD: CVE-2009-5039

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-5039
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-5039
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201101-025
value: HIGH

Trust: 0.6

VULHUB: VHN-42485
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-5039
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: CVE-2009-5039
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-42485
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-42485 // JVNDB: JVNDB-2011-001124 // CNNVD: CNNVD-201101-025 // NVD: CVE-2009-5039

PROBLEMTYPE DATA

problemtype:CWE-772

Trust: 1.1

problemtype:CWE-399

Trust: 0.9

sources: VULHUB: VHN-42485 // JVNDB: JVNDB-2011-001124 // NVD: CVE-2009-5039

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201101-025

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201101-025

CONFIGURATIONS

[
  {
    "CVE_data_version": "4.0",
    "nodes": [
      {
        "operator": "OR",
        "cpe_match": [
          {
            "vulnerable": true,
            "cpe22Uri": "cpe:/o:cisco:ios"
          }
        ]
      }
    ]
  }
]

sources: JVNDB: JVNDB-2011-001124

PATCH

title:22291url:http://tools.cisco.com/security/center/viewAlert.x?alertId=22291

Trust: 0.8

title:Release Notes for Cisco 800 Series Routers with Cisco IOS Release 15.0(1)XAurl:http://www.ciscosystems.com/en/US/docs/ios/15_0/15_0x/15_01_XA/rn800xa.pdf

Trust: 0.8

title:Cisco IOS gk_circuit_info_do_in_acf Repair measures of function memory leakurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=118594

Trust: 0.6

sources: JVNDB: JVNDB-2011-001124 // CNNVD: CNNVD-201101-025

EXTERNAL IDS

db:NVDid:CVE-2009-5039

Trust: 2.8

db:VUPENid:ADV-2011-0129

Trust: 0.8

db:XFid:64731

Trust: 0.8

db:JVNDBid:JVNDB-2011-001124

Trust: 0.8

db:CNNVDid:CNNVD-201101-025

Trust: 0.7

db:BIDid:45758

Trust: 0.4

db:VULHUBid:VHN-42485

Trust: 0.1

sources: VULHUB: VHN-42485 // BID: 45758 // JVNDB: JVNDB-2011-001124 // CNNVD: CNNVD-201101-025 // NVD: CVE-2009-5039

REFERENCES

url:http://www.cisco.com/en/us/docs/ios/15_0/15_0x/15_01_xa/rn800xa.pdf

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/64731

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-5039

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/64731

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-5039

Trust: 0.8

url:http://www.vupen.com/english/advisories/2011/0129

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-42485 // BID: 45758 // JVNDB: JVNDB-2011-001124 // CNNVD: CNNVD-201101-025 // NVD: CVE-2009-5039

CREDITS

Cisco

Trust: 0.3

sources: BID: 45758

SOURCES

db:VULHUBid:VHN-42485
db:BIDid:45758
db:JVNDBid:JVNDB-2011-001124
db:CNNVDid:CNNVD-201101-025
db:NVDid:CVE-2009-5039

LAST UPDATE DATE

2025-04-11T22:50:17.560000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-42485date:2020-05-13T00:00:00
db:BIDid:45758date:2009-10-27T00:00:00
db:JVNDBid:JVNDB-2011-001124date:2011-02-24T00:00:00
db:CNNVDid:CNNVD-201101-025date:2020-05-14T00:00:00
db:NVDid:CVE-2009-5039date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-42485date:2011-01-07T00:00:00
db:BIDid:45758date:2009-10-27T00:00:00
db:JVNDBid:JVNDB-2011-001124date:2011-02-24T00:00:00
db:CNNVDid:CNNVD-201101-025date:2011-01-10T00:00:00
db:NVDid:CVE-2009-5039date:2011-01-07T19:00:16.890