|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[sec-adv] Cisco Catalyst Switch Non-Standard TCP Flag Combination DoS Vulnerability
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Wed Jul 09 2003 - 09:25:07 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Cisco Catalyst Switch Non-Standard TCP Flag Combination DoS
Vulnerability
READ ONLINE:
http://www.secunia.com/advisories/9223/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
From local network
OPERATING SYSTEM:
Cisco CATOS 7.x
Cisco CATOS 5.x
Cisco CATOS 6.x
DESCRIPTION:
Cisco has reported a vulnerability in CatOS for various Catalyst
switches, which can be exploited by malicious people to cause a DoS
(Denial of Service) on certain active services on a vulnerable
device.
The vulnerability is caused due to an error in the handling of
certain TCP packets. This can be exploited by making just eight (8)
TCP connection attempts with a non-standard TCP flag combination to a
listening service. After receiving the connection attempts, the
service will stop responding to further connection attempts.
The vulnerability has been reported to affect the following Catalyst
models:
- Catalyst 4000 Series including models 2948G and 2980G/2980G-A
- Catalyst 5000 Series including models 2901, 2902 and 2926
- Catalyst 6000
SOLUTION:
Cisco has released upgraded CatOS versions. A patch matrix is
available at the web page (in the "Software Versions and Fixes"
section) referenced in "Original Advisory".
ORIGINAL ADVISORY:
http://www.cisco.com/warp/public/707/cisco-sa-20030709-swtcp.shtml
----------------------------------------------------------------------
Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
Contact details:
Web : http://www.secunia.com/
E-mail : support
secunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]