Home    |    View Topics    |    Search    |    Contact Us    |   



Category:   Device (Router/Bridge/Hub)  >   Cisco IOS Vendors:   Cisco
Cisco IOS XR BGP Update Processing Flaws Let Remote BGP Peers Deny Service
SecurityTracker Alert ID:  1022756
SecurityTracker URL:
CVE Reference:   CVE-2009-1154, CVE-2009-2056   (Links to External Site)
Updated:  Aug 31 2009
Original Entry Date:  Aug 20 2009
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): XR 3.4.0 - 3.8.1
Description:   Two vulnerabilities were reported in Cisco IOS XR. A remote user can cause denial of service conditions.

A remote user can send a specially crafted (long) BGP update message to cause the target device to reload [CVE-2009-1154].

Cisco has assigned Cisco Bug ID CSCtb05382 to this vulnerability.

If the Cisco IOS XR BGP process is configured to prepend a large number of AS Numbers to the AS path, the BGP process will crash [CVE-2009-2056].

Cisco has assigned Cisco Bug ID CSCtb12726 to this vulnerability.

[Editor's note: These two vulnerabilities and the previously reported IOS XR BGP vulnerability (Alert ID 1022739; CVE-2009-2055) have been combined under Cisco Bug ID CSCtb18562.]

Impact:   A remote user can cause the target device to crash and reload.
Solution:   The vendor has issued a fix.

A patch matrix is available in the vendor's advisory.

The vendor's advisory is available at:

Vendor URL: (Links to External Site)
Cause:   Input validation error, State error

Message History:   None.

 Source Message Contents

[Original Message Not Available for Viewing]

Go to the Top of This SecurityTracker Archive Page

Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, LLC