OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Enterasys XSR Security Routers DoS

From: Frederico Queiroz (fqueirozish.com.br)
Date: Fri Jul 02 2004 - 13:00:50 CDT


Description: Enterasys XSR Security Routers crash when passing a packet
with the option record route.

System Vulnerable: This vulnerability was found in XSR-1800 series.
(firmware 7.0.0.0)

Proof-of-concept: I've used Hping (http://www.hping.org/) to perform
this example:

hping3 -1 -G www.uol.com.br

Vendor at Brazil was informed about this.

Frederico Queiroz
Security Consultant/ISH Tecnologia
Phone: +55-27-3334-8900
E-mail: fqueirozish.com.br