Re: Cisco Vulnerability

From: Jay Hennigan (jay@west.net)
Date: Wed Jul 16 2003 - 19:35:52 GMT-3


On Wed, 16 Jul 2003, Kim Ed wrote:

> I heard many major ISPs are having emergency maintenances (code
> upgrade?).

Must have been my post to NANOG.

> I also hear that it is not realted to this bug below but can't be sure.
>
> http://www.cisco.com/warp/public/707/cisco-sa-20030709-swtcp.shtml
>
> The rumored vulnerability is IOS, not CatOS and supposedly causes a
> reload, not a telnet DoS.

Yep, sure was.

> Anyone knows about this?

Supposedly it has to do with wedging the input buffer. 75 malformed
packets lock it up. It may not in itself cause a reload but one may
be needed to recover.

It's all over IRC, not a peep yet from Cisco. Rumor is that they've
given advance notice to the major backbones and the rest of the world
won't become enclued until late tomorrow afternoon.

In other news, AT&T experienced some major flakiness a couple of hours
ago, and released a very vague statement about "some customers may have
experienced an impairment..." Their woes were rumored to be a fiber cut
but I haven't heard of any voice or non-IP AT&T problems.

-- 
Jay Hennigan - CCIE #7880 - Network Administration - jay@west.net
WestNet:  Connecting you to the planet.  805 884-6323      WB6RDV
NetLojix Communications, Inc.  -  http://www.netlojix.com/


This archive was generated by hypermail 2.1.4 : Wed Aug 06 2003 - 06:52:42 GMT-3