Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
BID:4191
Info
Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
| Bugtraq ID: | 4191 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Feb 27 2002 12:00AM |
| Credit: | This vulnerability announced in a Cisco Security Advisory on February 27, 2002. |
| Vulnerable: |
Cisco IOS 12.2T Cisco IOS 12.2 Cisco IOS 12.1T Cisco IOS 12.1E Cisco IOS 12.1 Cisco IOS 12.0T Cisco IOS 12.0ST Cisco IOS 12.0S Cisco IOS 12.0 Cisco IOS 11.1CC |
| Not Vulnerable: | |
Discussion
Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
IOS is the Internet Operating System, used on Cisco routers. It is distributed and maintained by Cisco.
Under some circumstances, Cisco IOS may leak information from previously routed packets that are still in memory. When a packet sent to a router has a MAC layer packet length shorter than that specified in the IP layer length, the packet is padded by the router before being routed. The data used to pad the packet is taken from other packets previously routed that are still in the router's memory. It should be noted that this problem occurs only when Cisco Express Forwarding is enabled.
IOS is the Internet Operating System, used on Cisco routers. It is distributed and maintained by Cisco.
Under some circumstances, Cisco IOS may leak information from previously routed packets that are still in memory. When a packet sent to a router has a MAC layer packet length shorter than that specified in the IP layer length, the packet is padded by the router before being routed. The data used to pad the packet is taken from other packets previously routed that are still in the router's memory. It should be noted that this problem occurs only when Cisco Express Forwarding is enabled.
Exploit / POC
Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
Solution:
Fixes available:
Cisco IOS 12.1E
Cisco IOS 12.2
Cisco IOS 12.0ST
Cisco IOS 12.0S
Cisco IOS 12.2T
Cisco IOS 12.1
Cisco IOS 11.1CC
Cisco IOS 12.0
Solution:
Fixes available:
Cisco IOS 12.1E
Cisco IOS 12.2
Cisco IOS 12.0ST
Cisco IOS 12.0S
Cisco IOS 12.2T
Cisco IOS 12.1
Cisco IOS 11.1CC
Cisco IOS 12.0
References
Cisco IOS Cisco Express Forwarding Session Information Leakage Vulnerability
References:
References: