The Last HOPE
-->
         
         
Email us! Subscribe to Liquidmatrix!

Reboot The Web

Thanks to this posting on Brian Krebs blog I found out about a new vulnerability posted by Cisco. Make that three vulnerabilities that have been made public by Cisco.

Most Internet service providers will stagger the installation of these patches so as not to disrupt customers’ online connectivity, but one of these flaws appears to be so easy to exploit that if the bad guys figure out how before ISP get around to patching then we could very likely see portions of the Internet go dark soon.

The vulns include “Crafted IP Option Vulnerability“:

Cisco routers and switches running Cisco IOSĀ® or Cisco IOS XR software may be vulnerable to a remotely exploitable crafted IP option Denial of Service (DoS) attack. Exploitation of the vulnerability may potentially allow for arbitrary code execution. The vulnerability may be exploited after processing an Internet Control Message Protocol (ICMP) packet, Protocol Independent Multicast version 2 (PIMv2) packet, Pragmatic General Multicast (PGM) packet, or URL Rendezvous Directory (URD) packet containing a specific crafted IP option in the packet’s IP header. No other IP protocols are affected by this issue.

Second we have: “IPv6 Routing Header Vulnerability

Processing a specially crafted IPv6 Type 0 Routing header can crash a device running Cisco IOS software. This vulnerability does not affect IPv6 Type 2 Routing header which is used in mobile IPv6. IPv6 is not enabled by default in Cisco IOS.

And lastly we have this nasty bugger “Crafted TCP Packet Can Cause Denial of Service“:

The Cisco IOS Transmission Control Protocol (TCP) listener in certain versions of Cisco IOS software is vulnerable to a remotely-exploitable memory leak that may lead to a denial of service condition.

This vulnerability only applies to traffic destined to the Cisco IOS device. Traffic transiting the Cisco IOS device will not trigger this vulnerability.

For those of you using Cisco devices (damn near most folks) please review these advisories and take your necessary steps.

Article Link

Tags: , , ,

Tag It: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Nasty JavaScript Code Can Zap iPhone/iPod Touch
  • Cisco IP Phone Denial Of Service
  • Cisco IP Phone SIP INVITE DoS
  • Your Router Crashing? Could Be XP SP3
  • Vista Koolaid
  • Leave a Comment