Description
Cisco just released three security bulletins
for address several vulnerabilities in Cisco Operating
System Software
(IOS). One of the vulnerability "Crafted IP OptionĄ¨
creates a potential means for hackers to attack on
a range of Cisco routers and switches running IOS.
Attacks would have worked by sending certain ICMP,
PIMv2, PGM or URD packets with a specific IP option
set to a Cisco device, and causing the hardware to
either crash or execute arbitrary code. The flaw applies
to most of the code base of IOS 12.0, 12.1 and 12.2.
For details about the bulletins, please refer to:
http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml
http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-tcp.shtml
http://www.cisco.com/warp/public/707/cisco-sa-20070124-IOS-IPv6.shtml
Suggested
Solutions
It is recommended to apply the fixes and workarounds
described in the Cisco Security Advisories and
Vulnerability Notes.
Detecting and mitigating cisco-sa-20070124-crafted-tcp
Detecting and mitigating cisco-sa-20070124-crafted-ip-option
Detecting and mitigating cisco-sa-20070124-IOS-IPv6
Source
Cisco
Systems
|