Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
BID:20597
Info
Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
| Bugtraq ID: | 20597 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-5425 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Jul 06 2016 02:06PM |
| Credit: | MUSecurity is credited with the discovery of this issue. |
| Vulnerable: |
XORP eXtensible Open Router Platform 1.3 XORP eXtensible Open Router Platform 1.2 |
| Not Vulnerable: | |
Discussion
Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
The eXtensible Open Router Platform (XORP) is prone to a remote denial-of-service vulnerability because the software fails to properly handle malformed OSPF link state advertisements.
Exploiting this issue allows remote, unauthenticated attackers to crash the application, denying further service to legitimate users.
eXtensible Open Router Platform versions 1.2 and 1.3 are vulnerable to this issue.
The eXtensible Open Router Platform (XORP) is prone to a remote denial-of-service vulnerability because the software fails to properly handle malformed OSPF link state advertisements.
Exploiting this issue allows remote, unauthenticated attackers to crash the application, denying further service to legitimate users.
eXtensible Open Router Platform versions 1.2 and 1.3 are vulnerable to this issue.
Exploit / POC
Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
Solution:
The vendor has released patches to address this issue.
Please see the vendor references for details.
XORP eXtensible Open Router Platform 1.2
XORP eXtensible Open Router Platform 1.3
Solution:
The vendor has released patches to address this issue.
Please see the vendor references for details.
XORP eXtensible Open Router Platform 1.2
-
XORP xorp_sa_06:01.ospf_1.2.patch
http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.2.patch
XORP eXtensible Open Router Platform 1.3
-
XORP xorp_sa_06:01.ospf_1.3.patch
http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.3.patch
References
Extensible Open Router Platform OSPFv2 Remote Denial of Service Vulnerability
References:
References:
- Denial of Service in XORP OSPFv2 [MU-200610-01] (musecurity)
- XORP Homepage (XORP)