Affected Systems:
Cisco IOS 12.2
Cisco IOS 12.1
Cisco IOS 12.0
Description:
Cisco Internet OS IOS) is the operating system used by Cisco devices.
Cisco Systems IOS has a vulnerability in parsing GRE packets containing GRE source route information. Remote attackers may cause devices to process packets incorrectly.
If a specially crafted GRE message is received, the IOS device does not verify whether the offset field points to the message. If the offset value is set to a negative value, IOS directly removes the offset from the integer that contains the full length of IP packets, leading to cross-border access overflow in the buffer zone.
If the ring buffer can be carefully filled by legal communication with an IP header at an appropriate offset, attackers can create a large length of IP packets in IOS.
Vendor patch:
Cisco
Currently, the vendor has released
Upgrade the patch to fix this security problem, please go to the vendor's home page download: http://www.cisco.com/
(T113)