CVE-2006-4650
Summary
| CVE | CVE-2006-4650 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-09 00:04:00 UTC |
| Updated | 2018-10-17 21:38:00 UTC |
| Description | Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios | 12.0 | All | All | All |
| Operating System | Cisco | Ios | 12.1 | All | All | All |
| Operating System | Cisco | Ios | 12.2 | All | All | All |
| Operating System | Cisco | Ios | 12.0 | All | All | All |
| Operating System | Cisco | Ios | 12.1 | All | All | All |
| Operating System | Cisco | Ios | 12.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Cisco IOS GRE Parsing Error May Let Remote Users Inject Packets | SECTRACK | securitytracker.com | |
| 28590 | OSVDB | www.osvdb.org | |
| Cisco IOS GRE Decapsulation Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| PHENOELIT | MISC | www.phenoelit.de | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityReason - Cisco IOS GRE issue | SREASON | securityreason.com | |
| Cisco Security Response to: Cisco IOS GRE Decapsulation Vulnerability [IP Tunneling] - Cisco Systems | CISCO | www.cisco.com | |
| Webmail- OVH | VUPEN | www.vupen.com | |
| Cisco IOS Multiple GRE Source Routing Vulnerabilities | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.