Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42952
  • Total Topics: 16150
  • Online Today: 4651
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: Cisco “patch Thursday”, six patches released...  (Read 2901 times)

0 Members and 2 Guests are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Cisco “patch Thursday”, six patches released...
« on: 27. March 2014., 20:38:46 »


Sysadmins can get themselves ready for a busy Cisco “patch Thursday”, after the Borg lobbed six patches out the door to deal with a range of denial-of-service (DoS) vulnerabilities in IOS.

The vulnerabilities – see here for a single list – are all scored a CVS base score better than 7 as being remotely exploitable without authentication: http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar14.html
Most boil down to how various bits of IOS handle (or don't handle) malformed packets.

Taking them one-by-one:

SIP DoS in IOS – Some SIP messages, even though they'd be considered “well-formed”, can trigger a device reload. IOS XE Software release 3.10.0S and 3.10.1S are affected and a fix is available.

Key exchange module – the Internet Key Exchange module, IKEv2, can be crashed with a malformed packet. Customers are advised to upgrade to a non-vulnerable version of IOS XE.

IOS NAT – Malformed DNS packets can crash the NAT in various IOS versions. Fixed versions are available.

IOS SSL VPNs – the SSL subsystem in IOS is vulnerable to crafted HTML requests “designed to consume memory to an affected device”. Various IOS 15.1, 15.2, 15.3 and 15.4 releases are affected, with fixes available.

IOS and IOS XE IPv6 stack – can be crashed with crafted IPv6 packets, with fixes available.

7600 Switch Processor with 10 Gbps Ethernet uplinks – crafted IP packets can crash the Kailash FPGA in versions prior to 2.6, with fixes available.

Happy network patch day, network admins!

(ElReg)

Samker's Computer Forum - SCforum.info

Cisco “patch Thursday”, six patches released...
« on: 27. March 2014., 20:38:46 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising