>> Cisco IOS Multiple VLAN Trunking Protocol Code Execution and DoS Vulnerabilities
Title : Cisco IOS Multiple VLAN Trunking Protocol Code Execution and DoS Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3600 CVE ID : CVE-2006-4774 - CVE-2006-4775 - CVE-2006-4776
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-13
Technical Description
Multiple vulnerabilities have been identified in Cisco IOS, which could be exploited by attackers to execute arbitrary commands or cause a denial of service.
The first issue is due to an error in the VLAN Trunking Protocol (VTP) feature that does not properly handle specially crafted summary packets received on a trunk enabled port, which could be exploited by attackers on the local network segment to cause a software reset.
The second flaw is due to a buffer overflow error in the VTP feature when processing a summary advertisement received on a trunk enabled port with a Type-Length-Value (TLV) element containing an overly long VLAN name (more than 100 characters), which could be exploited by attackers to cause a denial of service or execute arbitrary commands.
The third flaw is due to an integer wrap in the VTP feature when handling a specially crafted configuration revision, which could be exploited by attackers to cause certain changes to the VLAN database to not be properly propagated throughout the VTP domain.