Thursday, August 09, 2007

Cisco released several security advisories this week for various products

Cisco IOS and IOS XR are reportedly affected by a vulnerability that can be exploited to disclose sensitive information or cause a Denial of Service. The problem is due to an error when processing Ipv6 packets with a Type 0 routing header. Sending a specially crafted packet may lead to disclosure of a number of bytes of packet buffer memory, or to crash the device.
This vulnerability affects Cisco IOS 12.x and Cisco IOS XR 3.x products. Vendor patches have been released for some, but not all, affected devices.