Ispravljen je sigurnosni nedostatak vezan uz Cisco IOS XR. Spomenuti nedostatak moguće je iskoristiti za izvođenje DoS napada, a pogađa samo sljedeće Cisco proizvode: Cisco 9000 Series Aggregation Services Routers (ASR) Route Switch Processor (RSP440) te Cisco Carrier Routing System (CRS) Performance Route Processor (PRP).
Paket:
Cisco IOS XR 4.x
Operacijski sustavi:
Cisco IOS XR 3.x, Cisco IOS XR 4.x
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
Izvorni ID preporuke:
cisco-sa-20120530-iosxr
Izvor:
Cisco
Problem:
Propust je posljedica nepravilnog rukovanja posebno oblikovanim paketima.
Posljedica:
Zlonamjerni korisnik može iskoristiti navedeni propust za izvođenje napada uskraćivanjem usluge (DoS napad).
Rješenje:
Svim korisnicima se savjetuje korištenje službene nadogradnje.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Advisory ID: cisco-sa-20120530-iosxr
Revision 1.0
For Public Release 2012 May 30 16:00 UTC (GMT)
+---------------------------------------------------------------------
Summary
=======
Cisco IOS XR Software contains a vulnerability when handling crafted
packets that may result in a denial of service condition. The
vulnerability only exists on Cisco 9000 Series Aggregation Services
Routers (ASR) Route Switch Processor (RSP440) and Cisco Carrier
Routing System (CRS) Performance Route Processor (PRP). The
vulnerability is a result of improper handling of crafted packets and
could cause the route processor, which processes the packets, to be
unable to transmit packets to the fabric.
Cisco has released free software updates that address this
vulnerability. This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120530-iosxr
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
iF4EAREIAAYFAk/GMvQACgkQQXnnBKKRMNDF2wD6A5yZWmZgCmk5x+RJ2mxIXzcW
RXsu7/NENNspgbOJk2wA/RIJ9Fbzy+QZTRuQtg2vX0vCOhterMOVmN3Ue0VCzj52
=lCxE
-----END PGP SIGNATURE-----
_______________________________________________
cust-security-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
To unsubscribe, send the command "unsubscribe" in the subject of your message to
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke