Vulnerability Note VU#274760
Cisco IOS fails to properly process specially crafted IPv6 packets
Overview
Cisco IOS fails to properly process IPv6 packets with specially crafted routing headers. Successful exploitation of this vulnerability may allow an attacker to execute code, or create a denial-of-service condition.
Description
Internet Protocol version 6 (IPv6) is a IP standard that is designed to replace the Internet Protocol version 4 (IPv4). IPv6 Type 0 Routing headers can store multiple addresses and are processed by routers for generalized source routing. Cisco IOS software contains a vulnerability that occurs when proccessing IPv6 Type 0 Routing headers. An attacker may be able to trigger this vulnerability by sending an IP packet with a speciallly crafted IPv6 Type 0 Routing header to a vulnerable system. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary code on an affected device, or create a denial of service condition. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Cisco Systems, Inc. | Affected | - | 24 Jan 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.cisco.com/warp/public/707/cisco-sa-20070124-IOS-IPv6.shtml
- http://www.cisco.com/en/US/products/products_security_response09186a00807cb0df.html#routers
- http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml#workarounds
- http://www.cisco.com/web/about/ac123/ac147/ac174/ac197/about_cisco_ipj_archive_article09186a00800c830a.html
- http://www.cisco.com/en/US/products/products_security_response09186a00807cb0df.html
- http://www.cisco.com/warp/public/707/cisco-sa-20070124-bundle.shtml
- http://en.wikipedia.org/wiki/IPv6
- http://en.wikipedia.org/wiki/Mobile_IPv6
- http://www.ietf.org/rfc/rfc2460.txt
- http://secunia.com/advisories/23867/
- http://www.securityfocus.com/bid/22210
- http://www.cisco.com/en/US/products/sw/iosswrel/products_ios_cisco_ios_software_category_home.html
Credit
Thanks to Cisco for information used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 24 Jan 2007
- Date First Published: 24 Jan 2007
- Date Last Updated: 25 Jan 2008
- Severity Metric: 5.94
- Document Revision: 26
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.