Description
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Affected products
- Cisco / cbos12.1 – 12.1
- Cisco / cbos12.2 – 12.2
- Cisco / cbos
- Cisco / cli
- Cisco / ids
- Cisco / IOS11.2 – 11.2
- Cisco / IOS12.0 – 12.0
- Cisco / IOS12.2 – 12.2
- Cisco / IOS12.3 – 12.3
- Cisco / IOS12.4 – 12.4
- Cisco / IOS12.1 – 12.1
- Cisco / IOS10.0 – 10.0
- Cisco / IOS10.3 – 10.3
- Cisco / IOS11.0 – 11.0
- Cisco / IOS11.1 – 11.1
- Cisco / ios_xr
- Cisco / ios_xr2.0 – 2.0
- Cisco / ios_xr3.0 – 3.0
- Cisco / ios_xr3.1 – 3.1
- Cisco / ios_xr3.2 – 3.2
- Cisco / ios_xr3.3 – 3.3
- Cisco / ios_xr3.4 – 3.4
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/26798
- MISChttp://www.securityfocus.com/bid/25352
- MISChttp://www.securitytracker.com/id?1018685
- MISChttps://puck.nether.net/pipermail/cisco-nsp/2007-August/043002.html
- MISChttp://www.heise-security.co.uk/news/94526/
- MISChttps://puck.nether.net/pipermail/cisco-nsp/2007-August/043010.html
- VENDOR_ADVISORYhttp://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=WAN%2C%20Routing%20and%20Switching&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddf7bc9
- VENDOR_ADVISORYhttp://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/3136