40
Condition: The PKCS#7 parsing code does not handle missing inner EncryptedContent
correctly. An attacker can craft malformed PKCS#7 blobs with missing content and trigger a
NULL pointer dereference on parsing.
Symptom: CVE-2015-1791
Condition: If a NewSessionTicket is received by a multi-threaded client when attempting to
reuse a previous ticket then a race condition can occur potentially leading to a double free of the
ticket data.
Symptom: CVE-2015-1792
Condition: When verifying a signedData message the CMS code can enter an infinite loop. This
can be used to perform denial of service against any system which verifies signedData
messages using the CMS code.
201510130373
Symptom: SIP calls cannot be placed if the router receives INVITE requests with no SDP
information.
Condition: This symptom might occur if the router receives INVITE requests with no SDP
information.
201507200041
Symptom: The router sends a SIP response message that contains an incorrect call release
cause code if the router receives an INVITE request with SDP information that contains the
video capability.
Condition: This symptom might occur if the router receives an INVITE request with SDP
information that contains the video capability.
201508100249
Symptom: The display voice sip call command outputs nothing if an MSR4000 router is a
single-chassis IRF fabric and uses the chassis number 2.
Condition: This symptom might occur if an MSR4000 router is a single-chassis IRF fabric and
uses the chassis number 2.
201508190420
Symptom: Memory leaks occur if the voice card is rebooted at the CLI when the CPU usage is
100%.
Condition: This symptom might occur if the voice card is rebooted at the CLI when the CPU
usage is 100%.
201510270033
Symptom: Upgrading the standby MPU of the MSR4000 router fails.
Condition: This symptom might occur if the active MPU only has an .ipe startup image file, and
the boot-loader command specifies the .ipe file for upgrading the standby MPU.
Resolved problems in CMW710-R0305
201509070388
Symptom: A fiber port cannot come up if a 100-Mbps optical transceiver module is installed in
the port and the speed 100 command is executed on the port.
Condition: This symptom might occur if a 100-Mbps optical transceiver module is installed in the
port and the speed 100 command is executed on the port.