U radu Cisco ASA 5500 Series Adaptive Security uređaja (Cisco ASA) te Cisco Catalyst 6500 Series ASA Services modula (Cisco ASASM) otkriven je sigurnosni propust kojeg zlonamjerni korisnik može iskoristiti za izvođenje DoS napada.
Paket:
Cisco ASA 5500 Series Adaptive Security Appliances , Cisco Catalyst 6500 Series ASA Services Module
Operacijski sustavi:
Cisco ASA 5500 Series Adaptive Security Appliances , Cisco Catalyst 6500 Series switches
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
lokalno/udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-3058
Izvorni ID preporuke:
cisco-sa-20120620-asaipv6
Izvor:
Cisco
Problem:
Do propusta dolazi zbog nepravilne obrade određenih IPv6 podataka. Za sada nisu poznati detaljniji uzroci ranjivosti.
Posljedica:
Propust je moguće iskoristiti za ponovno pokretanje ranjivih uređaja.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst
6500 Series ASA Services Module Denial of Service Vulnerability
Advisory ID: cisco-sa-20120620-asaipv6
Revision 1.0
For Public Release 2012 June 20 16:00 UTC (GMT)
+---------------------------------------------------------------------
Summary
=======
Cisco ASA 5500 Series Adaptive Security Appliances (Cisco ASA) and
Cisco Catalyst 6500 Series ASA Services Module (Cisco ASASM) contain a
vulnerability that may allow an unauthenticated, remote attacker to
cause the reload of the affected device.
Cisco has released free software updates that address this
vulnerability. Workarounds that mitigate this vulnerability are
available.
This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120620-asaipv6
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
iF4EAREIAAYFAk/hxbwACgkQQXnnBKKRMNDlHQD/ZgbXyT+BpLLekWVNXpDchrth
Ak5JDY58r4n1UxWAdvkA/A0mVVmObudC4/lut8eALOAzHFXPE1liRsUNACuEY1dU
=gzt0
-----END PGP SIGNATURE-----
_______________________________________________
cust-security-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
To unsubscribe, send the command "unsubscribe" in the subject of your message to
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke