[Tfug] Cisco 600 series.

Chris Hilton tfug@tfug.org
Tue Jun 4 12:04:02 2002


On Tue, 4 Jun 2002 10:48:42 -0700 (MST)
"Jon" <bigj@flatwan.net> wrote:

> Nice article about the Cisco series 600 running CBOS and it's huge
> vulnerbilities. Article is new but I think most of us know about some
> of these already. In any case here it is:
> 
> http://www.cisco.com/warp/public/707/CBOS-DoS.shtml
> 
> 
> Jon

Jon-

You can fix all the vulnerabilities in this article (and a couple more)
by upgrading to cbos 2.4.5 which Qwest has (finally)  so graciously
(sic) made available on their dsl customer support website.  The article
doesn't even cover all the vulnerabilities current at the time it was
written.  The release notes for the cbos upgrade list include these as
well:

Resolved Issues
===========

 -  CSCdv09928
    CBOS parser allows invalid port numbers to be specified

 -  CSCdv06092    
    Web services will respond to a directed broadcast request on subnet 

 -  CSCdx16962    
    ppp memory utilization increase after multiple train cycles

 -  CSCdx35237
    large packet causes PPP termination, incorrect EchoReq timer

 -  CSCdx36121
    TCP memory exhaustion after receiving large packet

 -  CSCdx51594
    DHCP lease expiration timer not decrementing properly

 -  CSCdx61253
    Bridging mode fails when certain configurations enabled

Add one or two that weren't made public and maybe they got em all for
now.  Heh.

-C-