Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
BID:28999
Info
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
| Bugtraq ID: | 28999 |
| Class: | Design Error |
| CVE: |
CVE-2007-6372 CVE-2008-2169 CVE-2008-2170 CVE-2008-2171 CVE-2008-2172 CVE-2008-2173 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | This issue was originally discussed on the Juniper for Network Service Providers list by a variety of sources. |
| Vulnerable: |
Hitachi GR4000 Hitachi GR3000 Hitachi GR2000-BH Hitachi GR2000-2B+ Hitachi GR2000-2B Hitachi GR2000-1B Hitachi AlaxalA AX ALAXALA Networks AX7800S ALAXALA Networks AX7800R ALAXALA Networks AX7700R 0 ALAXALA Networks AX5400S ALAXALA Networks AX3600S 0 ALAXALA Networks AX2400S 0 ALAXALA Networks AX2000R 0 |
| Not Vulnerable: | |
Discussion
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
Multiple vendors' BGP implementations are prone to a remote denial-of-service vulnerability that arises when the software handles specially crafted BGP packets.
NOTE: This issue is related to the vulnerability discussed in BID 26869 (Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability). It has been assigned its own record because details regarding what technologies are vulnerable and how the various vendors have implemented BGP are not currently available. As more information emerges, we will create individual records to further document the vulnerability for the various vulnerable technologies.
AlaxalA Networks AX series and Hitachi GR series are reported vulnerable to this issue. Unspecified technologies from Avici Systems, Inc., Century Systems Inc., and Yamaha Corporation are also reported vulnerable.
Multiple vendors' BGP implementations are prone to a remote denial-of-service vulnerability that arises when the software handles specially crafted BGP packets.
NOTE: This issue is related to the vulnerability discussed in BID 26869 (Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability). It has been assigned its own record because details regarding what technologies are vulnerable and how the various vendors have implemented BGP are not currently available. As more information emerges, we will create individual records to further document the vulnerability for the various vulnerable technologies.
AlaxalA Networks AX series and Hitachi GR series are reported vulnerable to this issue. Unspecified technologies from Avici Systems, Inc., Century Systems Inc., and Yamaha Corporation are also reported vulnerable.
Exploit / POC
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability
References:
References: