Cisco Carrier Routing System Bugs Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1027006 |
|
SecurityTracker URL: http://securitytracker.com/id/1027006
|
|
CVE Reference:
CVE-2011-3283, CVE-2011-3295
(Links to External Site)
|
Date: May 2 2012
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in Cisco Carrier Routing System. A remote user can cause denial of service conditions.
A remote user can send specially crafted network traffic to trigger a flaw in the NETIO and IPV4_IO processes and cause excessive CPU consumption on the target device [CVE-2011-3295]. Cisco has assigned Bug ID CSCti59888 to this vulnerability.
A remote user can send a specially crafted fragmented GRE packet to cause the Metro subsystem crash [CVE-2011-3283]. Cisco has assigned Bug ID CSCts14887 to this vulnerability.
|
Impact:
A remote user can cause excessive CPU consumption on the target system.
A remote user can cause the Metro subsystem crash.
|
Solution:
The vendor has issued a fix.
The vendor's advisories are available at:
http://www.cisco.com/cisco/software/release.html?mdfid=280777815&softwareid=280867577&release=3.9.1
http://www-europe.cisco.com/cisco/software/release.html?mdfid=279879106&reltype=all&relind=AVAILABLE&release=3.9.2&softwareid=280867577&sortparam=7
|
Vendor URL: www.cisco.com/ (Links to External Site)
|
Cause:
Not specified
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 02 May 2012 21:33:24 +0000
Subject: Cisco Carrier Routing System
|
<item type="CAN" name="CVE-2011-3283" seq="2011-3283">
<status>Candidate</status>
<phase date="20110829">Assigned</phase>
<desc>Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887.</desc>
<refs>
<ref source="CONFIRM" url="http://www.cisco.com/cisco/software/release.html?mdfid=280777815&softwareid=280867577&release=3.9.1">http://www.cisco.com/cisco/software/release.html?mdfid=280777815&softwareid=280867577&release=3.9.1</ref>
</refs>
<votes>
</votes>
<comments>
</comments>
</item>
<item type="CAN" name="CVE-2011-3295" seq="2011-3295">
<status>Candidate</status>
<phase date="20110829">Assigned</phase>
<desc>The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.</desc>
<refs>
<ref source="CONFIRM" url="http://www-europe.cisco.com/cisco/software/release.html?mdfid=279879106&reltype=all&relind=AVAILABLE&release=3.9.2&softwareid=280867577&sortparam=7">http://www-europe.cisco.com/cisco/software/release.html?mdfid=279879106&reltype=all&relind=AVAILABLE&release=3.9.2&softwareid=280867577&sortparam=7</ref>
</refs>
<votes>
</votes>
<comments>
</comments>
</item>
|
|