sky 发表于 2004-10-5 09:16:10

Cisco IOS畸形OSPF包 存在远程拒绝服务漏洞

  Cisco IOS是运行于很多Cisco设备操作系统。Cisco IOS处理畸形OSPF包时存在问题,远程攻击者可以利用这个漏洞使设备重载,产生拒绝服务。<br><br>  OSPF是RFC 2328定义的路由协议,设计用于管理AS内的IP路由。部分CISCO IOS在处理OSPF包时存在一个漏洞,可导致系统重载。要成功利用此漏洞攻击者必须知道配置在接口上的几个参数,如OSPF Area号码、Netmask、hello和dead timers。<br><br>  受影响系统:<br><br>  Cisco IOS 12.3 &#40;5&#41;B1<br><br>  Cisco IOS 12.3 &#40;4&#41;XQ<br><br>  Cisco IOS 12.3 &#40;4&#41;XK<br><br>  Cisco IOS 12.3 &#40;4&#41;XH<br><br>  Cisco IOS 12.3 &#40;4&#41;XG1<br><br>  Cisco IOS 12.3 &#40;4&#41;XD2<br><br>  Cisco IOS 12.3 &#40;4&#41;T4<br><br>  Cisco IOS 12.3 &#40;4&#41;EO1<br><br>  Cisco IOS 12.3 &#40;2&#41;XC3<br><br>  Cisco IOS 12.2 &#40;21&#41;<br><br>  Cisco IOS 12.2 &#40;20&#41;S1<br><br>  Cisco IOS 12.2 &#40;20&#41;S<br><br>  Cisco IOS 12.0SX<br><br>  Cisco IOS 12.0S<br><br>  不受影响系统:<br><br>  Cisco IOS 11.3XA<br><br>  Cisco IOS 11.3WA4<br><br>  Cisco IOS 11.3T<br><br>  Cisco IOS 11.3NA<br><br>  Cisco IOS 11.3MA<br><br>  Cisco IOS 11.3HA<br><br>  Cisco IOS 11.3DB<br><br>  Cisco IOS 11.3DA<br><br>  Cisco IOS 11.3 AA<br><br>  Cisco IOS 11.3.1T<br><br>  Cisco IOS 11.3.1ED<br><br>  Cisco IOS 11.3.11b<br><br>  Cisco IOS 11.3.1<br><br>  Cisco IOS 11.3&#40;2&#41;XA<br><br>  Cisco IOS 11.3 &#40;11b&#41;<br><br>  Cisco IOS 11.3<br><br>  Cisco IOS 11.2WA3<br><br>  Cisco IOS 11.2SA<br><br>  Cisco IOS 11.2P<br><br>  Cisco IOS 11.2GS<br><br>  Cisco IOS 11.2F<br><br>  Cisco IOS 11.2 BC<br><br>  Cisco IOS 11.2.9XA<br><br>  Cisco IOS 11.2.9P<br><br>  Cisco IOS 11.2.8SA5<br><br>  Cisco IOS 11.2.8SA3<br><br>  Cisco IOS 11.2.8SA1<br><br>  Cisco IOS 11.2.8P<br><br>  Cisco IOS 11.2.8<br><br>  Cisco IOS 11.2.4F1<br><br>  Cisco IOS 11.2.4F<br><br>  Cisco IOS 11.2.4<br><br>  Cisco IOS 11.2.10BC<br><br>  Cisco IOS 11.2.10<br><br>  Cisco IOS 11.2&#40;9&#41;XA<br><br>  Cisco IOS 11.2&#40;4&#41;XAf<br><br>  Cisco IOS 11.2&#40;4&#41;XA<br><br>  Cisco IOS 11.2&#40;4&#41;<br><br>  Cisco IOS 11.2&#40;19&#41;GS0.2<br><br>  Cisco IOS 11.2&#40;17&#41;<br><br>  Cisco IOS 11.2&#40;11&#41;<br><br>  Cisco IOS 11.2 &#40;26a&#41;<br><br>  Cisco IOS 11.2<br><br>  Cisco IOS 11.1IA<br><br>  Cisco IOS 11.1 CT<br><br>  Cisco IOS 11.1 CC<br><br>  Cisco IOS 11.1 CA<br><br>  Cisco IOS 11.1 AA<br><br>  Cisco IOS 11.1.9IA<br><br>  Cisco IOS 11.1.7CA<br><br>  Cisco IOS 11.1.7AA<br><br>  Cisco IOS 11.1.7<br><br>  Cisco IOS 11.1.17CT<br><br>  Cisco IOS 11.1.17CC<br><br>  Cisco IOS 11.1.16IA<br><br>  Cisco IOS 11.1.16AA<br><br>  Cisco IOS 11.1.16<br><br>  Cisco IOS 11.1.15IA<br><br>  Cisco IOS 11.1.15 CA<br><br>  Cisco IOS 11.1.15 AA<br><br>  Cisco IOS 11.1.15<br><br>  Cisco IOS 11.1.13IA<br><br>  Cisco IOS 11.1.13 CA<br><br>  Cisco IOS 11.1.13 AA<br><br>  Cisco IOS 11.1.13<br><br>  Cisco IOS 11.1&#40;36&#41;CC2<br><br>  Cisco IOS 11.1 &#40;24a&#41;<br><br>  Cisco IOS 11.1<br><br>  Cisco IOS 11.0x<br><br>  Cisco IOS 11.0.x<br><br>  Cisco IOS 11.0.20.3<br><br>  Cisco IOS 11.0.17BT<br><br>  Cisco IOS 11.0.17<br><br>  Cisco IOS 11.0.12&#40;a&#41;BT<br><br>  Cisco IOS 11.0.12<br><br>  Cisco IOS 11.0 &#40;22a&#41;<br><br>  Cisco IOS 11.0 &#40;18&#41;<br><br>  Cisco IOS 11.0<br><br>  Cisco IOS 10.3.4.3<br><br>  Cisco IOS 10.3.4.2<br><br>  Cisco IOS 10.3.3.4<br><br>  Cisco IOS 10.3.3.3<br><br>  Cisco IOS 10.3.19a<br><br>  Cisco IOS 10.3.16<br><br>  Cisco IOS 10.3<br><br>  补丁下载:<br><br>  Cisco已经为此发布了一个安全公告(cisco-sa-20040818-ospf)以及相应补丁:<br><br>  cisco-sa-20040818-ospf:Cisco IOS Malformed OSPF Packet Causes Reload<br><br>  链接:http://www.cisco.com/warp/public/707/cisco-sa-20040818-ospf.shtml

sky 发表于 2004-10-5 09:17:17

sky 发表于 2004-10-5 09:21:59

好久没SBB入帐了,呵呵,灌水
页: [1]
查看完整版本: Cisco IOS畸形OSPF包 存在远程拒绝服务漏洞