12 messages in net.nether.puck.cisco-nsp[c-nsp] Cisco Security Advisory: Cisc...
FromSent OnAttachments
Cisco Systems Product Security Incident Response TeamJan 26, 2005 12:25 pm 
Randy BushJan 26, 2005 10:12 pm 
Oliver Boehmer (oboehmer)Jan 27, 2005 12:55 am 
Randy BushJan 27, 2005 1:44 am 
Pekka SavolaJan 27, 2005 3:45 am 
Gert DoeringJan 27, 2005 4:15 am 
Dave McGaughJan 27, 2005 10:39 am 
Johannes ReschJan 27, 2005 10:46 am 
Ted MittelstaedtJan 28, 2005 2:36 am 
Ted MittelstaedtJan 28, 2005 2:39 am 
Oliver Boehmer (oboehmer)Jan 28, 2005 4:41 am 
Randy BushJan 30, 2005 7:54 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[c-nsp] Cisco Security Advisory: Cisco IOS Misformed BGP Packet Causes ReloadActions...
From:Gert Doering (ge@greenie.muc.de)
Date:Jan 27, 2005 4:15:19 am
List:net.nether.puck.cisco-nsp

Hi,

On Thu, Jan 27, 2005 at 10:45:27AM +0200, Pekka Savola wrote:

On Wed, 26 Jan 2005, Cisco Systems Product Security Incident Response Team
wrote:

|------------+-------------+-------------| | | 12.0(26)S5 | | | |-------------+-------------| | | 12.0(27)S4 | | |12.0S |-------------+-------------| | | 12.0(28)S1 | | | |-------------+-------------| | | | 12.0(29)S | |------------+-------------+-------------|

This is unclear. Is 12.0(21)Sx affected, but not fixed (i.e., the images before the BGP revamp)? I suppose 22-25S are affected but not fixed?

"This vulnerability is present in any unfixed version of Cisco IOS, from the beginning of support for the BGP protocol, including versions 9.x, 10.x, 11.x and 12.x."

|------------+-------------+-------------| | 12.2S | | 12.2(25)S | |------------+-------------+-------------|

Likewise, are older 12.2S series affected (e.g., 18S), but just not fixed, and folks have to upgrade?

I assume that it is so, and dislike it.

gert