A remote overflow exists in IOS and CatOS. VTP allows an attacker to specify the revision number of the VTP information, which an attacker can set to 0x7FFFFFFF. When an admin updates VLAN information, the revision is incremented to 0x80000000 resulting in an integer overflow. With a specially crafted packet, an attacker can cause denial of service by blocking communication of VLAN changes resulting in a loss of availability.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version recommended by Cisco TAC, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.