>> Cisco IOS Packets Handling Remote Code Execution and Denial of Service Vulnerabilities
Title : Cisco IOS Packets Handling Remote Code Execution and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-0329 CVE ID : CVE-2007-0479 - CVE-2007-0480 - CVE-2007-0481
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-25
Technical Description
Multiple vulnerabilities have been identified in Cisco IOS, which could be exploited by remote attackers to cause a denial of service or compromise an affected device.
The first issue is due to an error when handling Internet Control Message Protocol (ICMP) packets, Protocol Independent Multicast version 2 (PIMv2) packets, Pragmatic General Multicast (PGM) packets, or URL Rendezvous Directory (URD) packets with a header containing a specially crafted IP option, which could be exploited by remote attackers to reload a vulnerable device or execute arbitrary commands.
The second vulnerability is due to a memory leak in the Transmission Control Protocol (TCP) listener when processing specially crafted packets sent to an IPv4 address assigned to a physical or virtual interface on a device, which could be exploited by attackers to exhaust all available memory resources, creating a denial of service condition.
The third issue is due to an error when processing specially crafted IPv6 Type 0 Routing headers, which could be exploited by attackers to crash a vulnerable device