IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
BID:65006
Info
IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
| Bugtraq ID: | 65006 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5385 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2013 12:00AM |
| Updated: | Aug 01 2013 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: |
IBM i 7.1 IBM i 6.1 |
| Not Vulnerable: | |
Discussion
IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
IBM i Operating System is prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
IBM i 6.1 and 7.1 are vulnerable.
IBM i Operating System is prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
IBM i 6.1 and 7.1 are vulnerable.
Exploit / POC
IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM i Operating System OSPFv2 Routing Protocol Remote Security Bypass Vulnerability
References:
References: