RE: Cisco IOS Denial of Service that affects most Cisco IOS routers- requires power cycle to recover

From: Darrell Kristof (darrell.kristofat_private)
Date: Thu Jul 17 2003 - 15:42:32 PDT

  • Next message: James Fields: "Re: Cisco IOS vulnerability"

    Cisco has updated the advisory to include details on the exploit.
    
    http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml
    
    Cisco routers are configured to process and accept Internet Protocol
    version 4 (IPv4) packets by default. A rare, specially crafted sequence
    of IPv4 packets with protocol type 53 (SWIPE), 55 (IP Mobility), 77 (Sun
    ND), or 103 (Protocol Independent Multicast - PIM) which is handled by
    the processor on a Cisco IOS device may force the device to incorrectly
    flag the input queue on an interface as full, which will cause the
    router to stop processing inbound traffic on that interface. This can
    cause routing protocols to drop due to dead timers. 
    
    
    - Darrell
    
    ======================================================================
    Darrell Kristof, CISSP, CCNP, TICSA
    Network Manager/Team Leader
    Whole Foods Market, Corporate Offices
    E-Mail: darrell.kristofat_private   
    
    
    
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Thu Jul 17 2003 - 22:15:54 PDT