XORP is "the eXtensible Open Router Platform". A vulnerability in the way XORP handles incoming OSPFv2 requests allows remote attackers to cause the program to no longer respond to legitimate requests effectively causing a denial of service against the product.
OSPF carries link state information using Link State Advertisements. Each LSA contains a length field as well as a checksum. XORP performs a checksum verification when processing an LSA. During the checksum verification, the length field is used to calculate the payload. An invalid length field causes an out of bounds read, causing the OSPF daemon to crash.
Vendor Response / Solution:
Apply the relevant patch to your XORP system and follow vendor instructions.