Re: PIX Firewall 5.1 DoS Vulnerability

From: Adam Rothschild (asrat_private)
Date: Fri Apr 13 2001 - 11:00:15 PDT

  • Next message: debian-security-announceat_private: "[SECURITY] [DSA-047-1] multiple kernel problems"

    On Wed, Apr 11, 2001 at 04:22:33PM -0700, Scott Raymond wrote:
    > By the way, I recently upgraded a PIX 515 at work.  The folks at
    > Cisco inform me that the latest software binary image, 5.3.1, is
    > broken.  They suggest upgrading to 5.2.5, which has all of the
    > updates in 5.3.1, including the elimination of the DoS
    > vulnerability.
    
    Interesting; definitely the first I've heard of this.  Do you have any
    details of this reported brokenness, or perhaps a Cisco bug ID to
    reference?
    
    > It also doesn't hurt to upgrade to fix the duplicate SMTP message
    > problem with PIX 4.x.
    
    Indeed.  Running 4.x code in this day and age is generally a bad
    thing(TM) for a number of reasons.
    
    -adam
    



    This archive was generated by hypermail 2b30 : Mon Apr 16 2001 - 01:36:29 PDT