Full Disclosure mailing list archives

Re: [c-nsp] Cisco Security Advisory: Crafted IP Option Vulnerability


From: "Justin Shore" <justin.shore () sktbcs com>
Date: Thu, 25 Jan 2007 22:47:25 -0600

Now that you mention it, I did have a Pix running 7.1.2 mysteriously
reboot twice today.  What are the odds that this vulnerability affects
more than just IOS 9-12?

Justin


-----Original Message-----
From: cisco-nsp-bounces () puck nether net
[mailto:cisco-nsp-bounces () puck nether net] On Behalf Of Andre Gironda

So it's too late.  Don't bother upgrading now; you're already owned.
Unless they are blocking it at the ISP borders in the same way they
blocked out the Cisco IPv4 Crafted DoS vulnerability in 2003.  ISP's
probably got the patch (or at least Cisco's ISP's did) a week ago.
Had rolling reboots lately?  Don't know why?  Lots of "miscellaneous"
ISP maintenace.  I wonder...

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: