Release date: 2012-05-10
Updated on:
Affected Systems:
Cisco IOS 15.1
Cisco IOS 15.0
Cisco IOS 12.0
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-4012
Cisco's Internet Operating System (IOS) is a complex operating system optimized for Internet connection.
Cisco IOS 12.0, 15.0, and 15.1 do not create shard entries when using Policy Feature Card 3C (PFC3C) to process ICMPv6 ACLs. Remote attackers can exploit this vulnerability to cause DOS.
<* Source: vendor
Link: http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notes/caveats_SXJ.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (caveats_SXJ) for this purpose and the corresponding patch:
Caveats_SXJ: Caveats in Release 12.2 (33) SXJ and Rebuilds
Link: http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notes/caveats_SXJ.html