Cisco IOS Software NAT for NetMeeting Directory (LDAP) Vulnerability
14 Mar. 2012
Summary
This allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic
.Vulnerable Systems:
* Cisco IOS Software NetMeeting Directory NAT (LDAP on TCP port 389)
LDAP is a protocol for querying and modifying data of directory services implemented in IP networks. NAT for NetMeeting Directory, also known as the Internet Locator Service (ILS), translates LDAP packets on TCP port 389. The inspected port is not configurable.
This vulnerability is triggered by malformed transit LDAP traffic that needs to be processed by the NAT for NetMeeting Directory feature.
Vendor Status:
Cisco has issued an update to correct this vulnerability
Disclosure Timeline:
2012-Feb-17 Updated information in Ciso IOS Software table for Cisco IOS 12.2SXH.
2011-Oct-21 Corrected back-end information regarding CSCtd10712. No change made in the Security Advisory itself.
2011-Sep-30 Updated information in fixed Cisco IOS Software table for releases 12.2MRB, 12.2SXH, 12.2SXI, 12.2SXJ, and 12.2SY.
2011-Sep-28 Initial public release.