Reactions to story from Vulnerability and Virus Information - Secunia
[3/5] Cisco IOS Multiple Vulnerabilities
http://secunia.com/ advisories/ 29507/
Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service). Be sure to check if your system is missing security updates or have insecure applications installed: http://secunia.com/software_inspector/ Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser.
Reactions / posts that link to this post
-
Cisco IOS Multiple Vulnerabilities
http://www.liquidmatrix.org/blog/2008/03/27/cisco-ios-multip...Out today are multiple vulnerabilities from Cisco. There are patches available from Cisco to tackle data manipulation and denial of service issues in their IOS. From Secunia: Description: Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service). 1) A memory leak exists in the handling of completed PPTP sessions, which can be exploited to exhaust memory on an affected system. 2) An error exists in the handling of PPTP sessions when virtual access interfaces are not removed from the interface descriptor block (IDB) and are not reused. This can result in an exhaustion of the interface descriptor block (IDB) limit. Vulnerabilities #1 and #2 are reported in Cisco IOS versions prior to 12.3 with VPDN enabled. 3) Some errors exist in the Data-Link-Switching (DLSw) feature when processing UDP and IP protocol 91 packets. This can be exploited to cause a reload of the system or a memory leak. 4) An error exists in the processing of IPv6 packets, which can be exploited to prevent the interface from receiving additional traffic or to cause the device to crash (if RSVP service is configured on the interface) by sending a specially crafted IPv6 packet to the device. Successful exploitation of this vulnerability requires that IPv6 and certain IPv4 UDP services are enabled. 5) An error exists in the implementation of Multicast Virtual Private Networks (MVPN), which can be exploited to create extra multicast states on the core routers via specially crafted Multicast Distribution Tree (MDT) Data Join messages. This can also be exploited to receive multicast traffic from VPNs that are not connected to the same Provider Edge (PE). Successful exploitation of the multicast traffic leak requires that the attacker knows or guesses the Border Gateway Protocol (BGP) peering IP address of a remote PE router and the address of the multicast group that is used in other MPLS VPNs. Ger yer patch on. Article Link
-
Cisco IOS Multiple Vulnerabilities
http://www.liquidmatrix.org/blog/2008/03/27/cisco-ios-multip...Out today are multiple vulnerabilities from Cisco. There are patches available from Cisco to tackle data manipulation and denial of service issues in their IOS. From Secunia: Description: Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service). 1) A memory leak exists in the handling of completed PPTP sessions, which can be exploited to exhaust memory on an affected system. 2) An error exists in the handling of PPTP sessions when virtual access interfaces are not removed from the interface descriptor block (IDB) and are not reused. This can result in an exhaustion of the interface descriptor block (IDB) limit. Vulnerabilities #1 and #2 are reported in Cisco IOS versions prior to 12.3 with VPDN enabled. 3) Some errors exist in the Data-Link-Switching (DLSw) feature when processing UDP and IP protocol 91 packets. This can be exploited to cause a reload of the system or a memory leak. 4) An error exists in the processing of IPv6 packets, which can be exploited to prevent the interface from receiving additional traffic or to cause the device to crash (if RSVP service is configured on the interface) by sending a specially crafted IPv6 packet to the device. Successful exploitation of this vulnerability requires that IPv6 and certain IPv4 UDP services are enabled. 5) An error exists in the implementation of Multicast Virtual Private Networks (MVPN), which can be exploited to create extra multicast states on the core routers via specially crafted Multicast Distribution Tree (MDT) Data Join messages. This can also be exploited to receive multicast traffic from VPNs that are not connected to the same Provider Edge (PE). Successful exploitation of the multicast traffic leak requires that the attacker knows or guesses the Border Gateway Protocol (BGP) peering IP address of a remote PE router and the address of the multicast group that is used in other MPLS VPNs. Ger yer patch on. Article Link
-
Cisco IOS Multiple Vulnerabilities
http://www.liquidmatrix.org/blog/2008/03/27/cisco-ios-multip...Out today are multiple vulnerabilities from Cisco. There are patches available from Cisco to tackle data manipulation and denial of service issues in their IOS. From Secunia: Description: Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service). 1) A memory leak exists in the handling of completed PPTP sessions, which can be exploited to exhaust memory on an affected system. 2) An error exists in the handling of PPTP sessions when virtual access interfaces are not removed from the interface descriptor block (IDB) and are not reused. This can result in an exhaustion of the interface descriptor block (IDB) limit. Vulnerabilities #1 and #2 are reported in Cisco IOS versions prior to 12.3 with VPDN enabled. 3) Some errors exist in the Data-Link-Switching (DLSw) feature when processing UDP and IP protocol 91 packets. This can be exploited to cause a reload of the system or a memory leak. 4) An error exists in the processing of IPv6 packets, which can be exploited to prevent the interface from receiving additional traffic or to cause the device to crash (if RSVP service is configured on the interface) by sending a specially crafted IPv6 packet to the device. Successful exploitation of this vulnerability requires that IPv6 and certain IPv4 UDP services are enabled. 5) An error exists in the implementation of Multicast Virtual Private Networks (MVPN), which can be exploited to create extra multicast states on the core routers via specially crafted Multicast Distribution Tree (MDT) Data Join messages. This can also be exploited to receive multicast traffic from VPNs that are not connected to the same Provider Edge (PE). Successful exploitation of the multicast traffic leak requires that the attacker knows or guesses the Border Gateway Protocol (BGP) peering IP address of a remote PE router and the address of the multicast group that is used in other MPLS VPNs. Ger yer patch on. Article Link
Rising items in IT
Headlines
- iPod Touch/iPhone for Music Round-up
- Decapitate Your USB Smart Dog Hub
- MSI Titan 700 PC Announced
- See Color With Sound
- CW to sell off Sunday night
- Dell to replace wonky keyboards
Gates: 140 Million copies of Vista sold
Despite Vista struggling with the publics perception, Microsoft Chairman Bill Gates is touting the OS rapid sales rate saying 140 million copies have been sold thus far.
More rising blog posts
More rising news stories
Recent posts from Vulnerability and Virus Information - Secunia
-
[3/5] TFTP Server SP Long Error Message Buffer Overflow
45 minutes ago -
[3/5] Zarafa Script Insertion Vulnerabilities
45 minutes ago -
[3/5] Maian Search Cross-Site Scripting and SQL Injection Vulnerabilities
45 minutes ago