|
|
|
Vulnerability Note VU#236045Cisco IOS Firewall Authentication Proxy vulnerable to buffer overflow via specially crafted user authentication credentialsOverviewA buffer overflow vulnerability in Cisco IOS Firewall Authentication Proxy may allow a remote unauthenticated attacker to execute arbitrary code or cause a denial of service.I. DescriptionCisco IOS Firewall Authentication Proxy is a feature that allows network administrators to apply security policies on a per-user basis. The Firewall Authentication Proxy for FTP and Telnet Sessions feature for Cisco IOS provides proxy authentication for FTP and Telnet services.Cisco IOS is vulnerable to a buffer overflow when processing user authentication credentials from an Authentication Proxy Telnet or FTP session. According to the Cisco Security Advisory, the following versions of Cisco IOS are affected:
II. ImpactA remote unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition on an affected system.III. SolutionApply a patch or upgradePlease refer to the "Software Versions and Fixes" section of the Cisco Security Advisory for more information on upgrading.
References
Thanks to Cisco Systems Product Security Incident Response Team for reporting this vulnerability. This document was written by Will Dormann, based on the Cisco Security Advisory.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||