OSVDB ID: 28776

Title: Cisco IOS VTP Revision Integer Wrap DoS

Info

Disclosure

Sep 13, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in IOS and CatOS. VTP allows an attacker to specify the revision number of the VTP information, which an attacker can set to 0x7FFFFFFF. When an admin updates VLAN information, the revision is incremented to 0x80000000 resulting in an integer overflow. With a specially crafted packet, an attacker can cause denial of service by blocking communication of VLAN changes resulting in a loss of availability.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Availability
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version recommended by Cisco TAC, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Cisco Systems, Inc.

IOS

12.1(19)

CatOS

Unspecified

References

Credit

  • FX - fxphenoelit.de - Phenoelit Group


Direct URL: http://osvdb.org/28776