Secunia Security Advisory - Cisco has acknowledged a vulnerability in Cisco Wireless Control System (WCS), which can be exploited by malicious people to compromise a vulnerable system.
46d6f46222c54a11345f3aa36dce501889b992cc65f691473e521756c8c5b140
----------------------------------------------------------------------
A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI
has been released. The new version includes many new and advanced
features, which makes it even easier to stay patched.
Download and test it today:
https://psi.secunia.com/
Read more about this new version:
https://psi.secunia.com/?page=changelog
----------------------------------------------------------------------
TITLE:
Cisco Wireless Control System Apache Tomcat JK Web Server Connector
Buffer Overflow
SECUNIA ADVISORY ID:
SA28711
VERIFY ADVISORY:
http://secunia.com/advisories/28711/
CRITICAL:
Moderately critical
IMPACT:
System access
WHERE:
>From local network
SOFTWARE:
Cisco Wireless Control System (WCS)
http://secunia.com/product/6332/
DESCRIPTION:
Cisco has acknowledged a vulnerability in Cisco Wireless Control
System (WCS), which can be exploited by malicious people to
compromise a vulnerable system.
For more information:
SA24398
The vulnerability affects versions 3.x and 4.0.x prior to 4.0.100.0,
and 4.1.x and 4.2.x prior to to version 4.2.62.0.
SOLUTION:
Update to the latest versions.
WCS for Linux and Windows 4.0.x and earlier:
Update to version 4.0.100.0.
WCS for Linux and Windows 4.1.91.0 and earlier:
Update to version 4.2.62.0.
ORIGINAL ADVISORY:
Cisco (100361):
http://www.cisco.com/warp/public/707/cisco-sa-20080130-wcs.shtml
OTHER REFERENCES:
SA24398:
http://secunia.com/advisories/24398/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------