|
Brought to you by:
Suppliers of:
|
|
|
| |
| XORP is "the eXtensible Open Router Platform". A vulnerability in the way XORP handles incoming OSPFv2 requests allows remote attackers to cause the program to no longer respond to legitimate requests effectively causing a denial of service against the product. |
| |
Credit:
The information has been provided by Mu Security.
The original article can be found at: http://labs.musecurity.com/advisories/MU-200610-01.txt
|
| |
OSPF carries link state information using Link State Advertisements. Each LSA contains a length field as well as a checksum. XORP performs a checksum verification when processing an LSA. During the checksum verification, the length field is used to calculate the payload. An invalid length field causes an out of bounds read, causing the OSPF daemon to crash.
Vendor Response / Solution:
Apply the relevant patch to your XORP system and follow vendor instructions.
[XORP 1.2]
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.2.patch
[XORP 1.3]
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.3.patch
History:
10/13/06 - First contact with vendor
10/16/06 - Patch available
10/17/06 - Advisory released
|
|
|
|
|