|
|
>> Cisco IOS Packets Processing Remote Denial of Service Vulnerability
|
Title : Cisco IOS Packets Processing Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-1005 CVE ID : CVE-2008-0537
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-28
|
A vulnerability has been identified in various Cisco products, which could be exploited by attackers to cause a denial of service. This issue is caused by an error when handling malformed packets while the device is configured for Multi Protocol Label Switching (MPLS) Virtual Private Networking (VPN) and Open Shortest Path First (OSPF) sham-link, which could be exploited by attackers to cause a vulnerable device to suffer from a blocked queue, leak memory, and/or restart, creating a denial of service condition.
Affected Products
Cisco Catalyst 6500 Series devices with the Sup32, Sup720, Sup720-3B, or Sup720-3BXL
Cisco 7600 Series devices with the Sup32, Sup720, Sup720-3B, or Sup720-3BXL
Cisco 7600 Series devices with the RSP720, RSP720-3C, or RSP720-3CXL
Cisco ME 6524 Ethernet Switch
Cisco IOS versions 12.x
Solution
Apply fixes :
http://www.cisco.com/warp/public/707/cisco-sa-20080326-queue.shtml
References
http://www.vupen.com/english/advisories/2008/1005 http://www.cisco.com/warp/public/707/cisco-sa-20080326-queue.shtml
Credits
Vulnerability reported by the vendor.
ChangeLog
2008-03-28 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|