navbarPDF
Strip_SecurityNotices

Cisco Security Response: PHP HTML Entity Encoder Heap Overflow Vulnerability in Multiple Web-Based Management Interfaces

Document ID: 82377

http://www.cisco.com/warp/public/707/cisco-sr-20070425-http.shtml

Revision 1.0

Last Updated 2007 April 25 1600 UTC (GMT)

For Public Release 2007 April 25 1600 UTC (GMT)


Please provide your feedback on this document.


Contents

Cisco Response
Additional Information
Revision History
Cisco Security Procedures

Cisco Response

This is a response to a Hardened-PHP Project advisory posted on November 3, 2006, entitled "PHP HTML Entity Encoder Heap Overflow Vulnerability." This advisory is available at the following link: http://www.hardened-php.net/advisory_132006.138.html.

Several Cisco devices leverage PHP HTML support and are affected by the described vulnerability. The affected devices are listed below.

There are no workarounds for this vulnerability.

Additional mitigations that can be deployed on Cisco devices within the network are available in the Cisco Applied Mitigation Bulletin companion document for this advisory at the following link: http://www.cisco.com/warp/public/707/cisco-amb-20070425-http.shtml.

This Cisco Security Response is posted at the following link: http://www.cisco.com/warp/public/707/cisco-sr-20070425-http.shtml.

Additional Information

The following products are affected by this vulnerability:

No other Cisco products are known to be affected by this vulnerability.

Workarounds

No workarounds exist for this vulnerability.

A best practice is to configure IP source restriction to valid source IP addresses of administrative clients that may access the affected devices. Administrators should restrict access to the web interface to only trusted client IP addresses or subnets.

Additional mitigations that can be deployed on Cisco devices within the network are available in the Cisco Applied Mitigation Bulletin companion document for this advisory at the following link: http://www.cisco.com/warp/public/707/cisco-amb-20070425-http.shtml

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Revision History

Revision 1.0

2007-April-25

Initial public release

Cisco Security Procedures

Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.


Toolbar

All contents are Copyright © 2006-2007 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.


Updated: Apr 25, 2007Document ID: 82377