Vulnerable Systems:
* Cisco Content Delivery System software versions 2.5.7 and later
Immune Systems:
* Cisco Content Delivery System software versions prior to 2.5.7
The Cisco Internet Streamer application, part of the Cisco CDS, contains a vulnerability on its web server component that could cause the web server engine to crash when processing specially crafted URLs.
An unauthenticated attacker may be able to exploit this vulnerability to cause a denial of service condition on the web server that is running on the Service Engine. The device will remain operational, and the Web Engine will restart if the attack stops.
This vulnerability is documented in the Cisco Bug IDs CSCtg67333 ( registered customers only) and CSCth25341 ( registered customers only) and has been assigned Common Vulnerabilities and Exposures (CVE) ID CVE-2011-1649. Both bugs fixes are required for a full solution.