Cisco IOS is Affected by Multiple Vulnerabilities |
---|
Monty Solomon (monty@roscom.com) Wed, 24 Jan 2007 22:43:41 -0500
|
|
Cisco IOS is Affected by Multiple Vulnerabilities
Original release date: January 24, 2007
Systems Affected
* Cisco network devices running IOS in various configurations
Overview
Several vulnerabilities have been discovered in Cisco's Internet
I. Description
Cisco has published three advisories describing flaws in IOS with
VU#217912 - Cisco IOS fails to properly process TCP packets
The Cisco IOS Transmission Control Protocol listener in certain
VU#341288 - Cisco IOS fails to properly prcoess certain packets
A vulnerability exists in the way Cisco IOS processes a number of
VU#274760 - Cisco IOS fails to properly process specially crafted IPv6
Cisco IOS fails to properly process IPv6 packets with specially
II. Impact
Although the resulting impacts of these three vulnerabilities is
Because devices running IOS may transmit traffic for a number of
Also in the case of VU#341288 and VU#274760, successful
III. Solution
Upgrade to a fixed version of IOS
Cisco has updated versions of its IOS software to address these
Workaround
Cisco has also published practical workarounds for these
Sites that are unable to install an upgraded version of IOS are
IV. References
* US-CERT Vulnerability Note VU#217912 -
* US-CERT Vulnerability Note VU#341288 -
* US-CERT Vulnerability Note VU#274760 -
* Cisco Security Advisory: Crafted TCP Packet Can Cause Denial of
* Cisco Security Advisory: Crafted IP Option Vulnerability -
* Cisco Security Advisory: Cisco Security Advisory: IPv6 Routing
The most recent version of this document can be found at:
<http://www.us-cert.gov/cas/techalerts/TA07-024A.html>
Feedback can be directed to US-CERT Technical Staff. Please send
Produced 2007 by US-CERT, a government organization.
Terms of use: |
Post Followup Article | Use your browser's quoting feature to quote article into reply |
Go to Next message: communicationsdirect_daily: "CommunicationsDirect News Daily Update - January 25, 2007" | |
Go to Previous message: Monty Solomon: "AACS Decryption Code Released" | |
TELECOM Digest: Home Page |