GRE Route Option resolution overflow vulnerability in Cisco IOS

Source: Internet
Author: User

Affected Systems:

Cisco IOS 12.2

Cisco IOS 12.1

Cisco IOS 12.0

Description:

Cisco Internet OS IOS) is the operating system used by Cisco devices.

Cisco Systems IOS has a vulnerability in parsing GRE packets containing GRE source route information. Remote attackers may cause devices to process packets incorrectly.

If a specially crafted GRE message is received, the IOS device does not verify whether the offset field points to the message. If the offset value is set to a negative value, IOS directly removes the offset from the integer that contains the full length of IP packets, leading to cross-border access overflow in the buffer zone.

If the ring buffer can be carefully filled by legal communication with an IP header at an appropriate offset, attackers can create a large length of IP packets in IOS.

Vendor patch:

Cisco

Currently, the vendor has released

Upgrade the patch to fix this security problem, please go to the vendor's home page download: http://www.cisco.com/

(T113)


Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.