Wednesday, March 25, 2009

Cisco released a "bundle"

Cisco has officially released a "bundle" of vulnerability notices for their IOS software. The issues related to these notifcations are varied and relate to TCP, UDP, Mobile and VPN vulnerabilities. We are reviewing them now and thought you may want to do the same.
The March 25, 2009, Cisco IOS Security Advisory bundled publication includes eight Security Advisories. All of the advisories address vulnerabilities in Cisco IOS Software. Each advisory lists the releases that correct the vulnerability or vulnerabilities in the advisory, and each security advisory also lists recommended releases that correct the vulnerabilities in the other seven advisories. The table in this document lists releases that correct all Cisco IOS Software vulnerabilities that have been published in Cisco Security Advisories on March 25, 2009, or earlier.A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers with the Cisco Tunneling Control Protocol (cTCP) encapsulation feature. Cisco has released free software updates that address this vulnerability. No workarounds are available; however, the IPSec NAT traversal (NAT-T) feature can be used as an alternative.
thoes Services Internet Marketing
* Cisco IOS cTCP DoS Vulnerability
* Cisco IOS Multiple Features IP Sockets Vulnerability
* Cisco IOS Mobile IP and Mobile IPv6 Vulnerabilities
* Cisco IOS Secure Copy Privilege Escalation Vulnerability
* Cisco IOS Session Initiation Protocol DoS Vulnerability
* Cisco IOS Multiple Features Crafted TCP Sequence Vulnerability
* Cisco IOS Multiple Features Crafted UDP Packet Vulnerability
* Cisco IOS WebVPN and SSLVPN Vulnerabilities

No comments:

Post a Comment