Cisco IOS接口不正确处理IPV4包远程拒绝服务漏洞

王朝other·作者佚名  2008-05-31
窄屏简体版  字體: |||超大  

Cisco IOS接口不正确处理IPV4包远程拒绝服务漏洞

严重程度:高

威胁程度:远程拒绝服务

错误类型:设计错误

利用方式:服务器模式

CVE(CAN) ID:CAN-2003-0567

受影响系统

Cisco IOS 12.2YH

Cisco IOS 12.2YG

Cisco IOS 12.2YF

Cisco IOS 12.2YD

Cisco IOS 12.2YC

Cisco IOS 12.2YB

Cisco IOS 12.2YA

Cisco IOS 12.2XW

Cisco IOS 12.2XT

Cisco IOS 12.2XS

Cisco IOS 12.2XR

Cisco IOS 12.2XQ

Cisco IOS 12.2XK

Cisco IOS 12.2XJ

Cisco IOS 12.2XI

Cisco IOS 12.2XH

Cisco IOS 12.2XG

Cisco IOS 12.2XF

Cisco IOS 12.2XE

Cisco IOS 12.2XD

Cisco IOS 12.2XC

Cisco IOS 12.2XB

Cisco IOS 12.2XA

Cisco IOS 12.2T

Cisco IOS 12.2DD

Cisco IOS 12.2BC

Cisco IOS 12.2(3)

Cisco IOS 12.2(2.2)T

Cisco IOS 12.2(2)XA

Cisco IOS 12.2(1b)

Cisco IOS 12.2(11)T

Cisco IOS 12.2(1.1)

Cisco IOS 12.2(1)XQ

Cisco IOS 12.2(1)XH

Cisco IOS 12.2(1)XD1

Cisco IOS 12.2(1)

Cisco IOS 12.2 YH

Cisco IOS 12.2 YG

Cisco IOS 12.2 YF

Cisco IOS 12.2 YC

Cisco IOS 12.2 YB

Cisco IOS 12.2 YA

Cisco IOS 12.2 XM

Cisco IOS 12.2 XL

Cisco IOS 12.2 XK

Cisco IOS 12.2 XJ

Cisco IOS 12.2 XI

Cisco IOS 12.2 XH

Cisco IOS 12.2 XE

Cisco IOS 12.2 XD

Cisco IOS 12.2 XC

Cisco IOS 12.2 S

Cisco IOS 12.2 MB

Cisco IOS 12.2 DA

Cisco IOS 12.2 BZ

Cisco IOS 12.2 BY

Cisco IOS 12.2 BC

Cisco IOS 12.2 (7a)

Cisco IOS 12.2 (7)DA

Cisco IOS 12.2 (7)

Cisco IOS 12.2 (5)

Cisco IOS 12.2 (4)B

Cisco IOS 12.2 (13.03)B

Cisco IOS 12.2 (12.05)T

Cisco IOS 12.2 (12.05)S

Cisco IOS 12.2 (12.05)

Cisco IOS 12.2 (12.02)T

Cisco IOS 12.2 (12.02)S

Cisco IOS 12.2

Cisco IOS 12.2

Cisco IOS 12.1YH

Cisco IOS 12.1YF

Cisco IOS 12.1YE

Cisco IOS 12.1YD

Cisco IOS 12.1YC

Cisco IOS 12.1YB

Cisco IOS 12.1YA

Cisco IOS 12.1XZ

Cisco IOS 12.1XY

Cisco IOS 12.1XX

Cisco IOS 12.1XW

Cisco IOS 12.1XV

Cisco IOS 12.1XU

Cisco IOS 12.1XT

Cisco IOS 12.1XS

Cisco IOS 12.1XR

Cisco IOS 12.1XQ

Cisco IOS 12.1XP

Cisco IOS 12.1XM

Cisco IOS 12.1XL

Cisco IOS 12.1XK

Cisco IOS 12.1XJ

Cisco IOS 12.1XI

Cisco IOS 12.1XH

Cisco IOS 12.1XG

Cisco IOS 12.1XF

Cisco IOS 12.1XE

Cisco IOS 12.1XD

Cisco IOS 12.1XC

Cisco IOS 12.1XB

Cisco IOS 12.1XA

Cisco IOS 12.1T

Cisco IOS 12.1EZ

Cisco IOS 12.1EY

Cisco IOS 12.1EX

Cisco IOS 12.1EC

Cisco IOS 12.1EA

Cisco IOS 12.1E

Cisco IOS 12.1DC

Cisco IOS 12.1DB

Cisco IOS 12.1DA

Cisco IOS 12.1CX

Cisco IOS 12.1AA

Cisco IOS 12.10S

Cisco IOS 12.1(9)E

Cisco IOS 12.1(8a)E

Cisco IOS 12.1(8)E

Cisco IOS 12.1(8)

Cisco IOS 12.1(7)

Cisco IOS 12.1(6.5)EC3

Cisco IOS 12.1(6)EZ1

Cisco IOS 12.1(6)EY

Cisco IOS 12.1(5)YF2

Cisco IOS 12.1(5)YD2

Cisco IOS 12.1(5)YC1

Cisco IOS 12.1(5)YB4

Cisco IOS 12.1(5)XY6

Cisco IOS 12.1(5)XV3

Cisco IOS 12.1(5)XU1

Cisco IOS 12.1(5)XS

Cisco IOS 12.1(5)XR2

Cisco IOS 12.1(5)XG5

Cisco IOS 12.1(5)T

Cisco IOS 12.1(5)DC

Cisco IOS 12.1(5)DB1

Cisco IOS 12.1(5)DA1

Cisco IOS 12.1(4.3)T

Cisco IOS 12.1(4)XM4

Cisco IOS 12.1(4)DC

Cisco IOS 12.1(4)DB1

Cisco IOS 12.1(4)DB

Cisco IOS 12.1(4)

Cisco IOS 12.1(3)XT3

Cisco IOS 12.1(3)XP4

Cisco IOS 12.1(2)E1

Cisco IOS 12.1(1a)T1

Cisco IOS 12.1(13.4)E

Cisco IOS 12.1(12)E

Cisco IOS 12.1(11)E

Cisco IOS 12.1(10)E

Cisco IOS 12.1(1.3)T

Cisco IOS 12.1 YC

Cisco IOS 12.1 YB

Cisco IOS 12.1 XG

Cisco IOS 12.1 XF

Cisco IOS 12.1 EY

Cisco IOS 12.1 EX

Cisco IOS 12.1 EW

Cisco IOS 12.1 EC

Cisco IOS 12.1 EA

Cisco IOS 12.1 E

Cisco IOS 12.1 (12b)

Cisco IOS 12.1 (11b)

Cisco IOS 12.1 (11)

Cisco IOS 12.1 (11)

Cisco IOS 12.1 (10a)

Cisco IOS 12.1 (10)E

Cisco IOS 12.1 (10)E

Cisco IOS 12.1 (10)E

Cisco IOS 12.1

Cisco IOS 12.1

Cisco IOS 12.0XW

Cisco IOS 12.0XV

Cisco IOS 12.0XU

Cisco IOS 12.0XS

Cisco IOS 12.0XR

Cisco IOS 12.0XQ

Cisco IOS 12.0XP

Cisco IOS 12.0XN

Cisco IOS 12.0XM

Cisco IOS 12.0XL

Cisco IOS 12.0XK

Cisco IOS 12.0XJ

Cisco IOS 12.0XI

Cisco IOS 12.0XH

Cisco IOS 12.0XG

Cisco IOS 12.0XF

Cisco IOS 12.0XE

Cisco IOS 12.0XD

Cisco IOS 12.0XC

Cisco IOS 12.0XB

Cisco IOS 12.0XA

Cisco IOS 12.0WT

Cisco IOS 12.0WC

Cisco IOS 12.0W5

Cisco IOS 12.0T

Cisco IOS 12.0SX

Cisco IOS 12.0ST

Cisco IOS 12.0SP

Cisco IOS 12.0SL

Cisco IOS 12.0SC

Cisco IOS 12.0S

Cisco IOS 12.0DC

Cisco IOS 12.0DB

Cisco IOS 12.0DA

Cisco IOS 12.0.7(T)

Cisco IOS 12.0.7

Cisco IOS 12.0.6

Cisco IOS 12.0.5

Cisco IOS 12.0.4T

Cisco IOS 12.0.4S

Cisco IOS 12.0.4

Cisco IOS 12.0.3T2

Cisco IOS 12.0.3

Cisco IOS 12.0.2XG

Cisco IOS 12.0.2XF

Cisco IOS 12.0.2XD

Cisco IOS 12.0.2XC

Cisco IOS 12.0.2

Cisco IOS 12.0.1XE

Cisco IOS 12.0.1XB

Cisco IOS 12.0.1XA3

Cisco IOS 12.0.1W

Cisco IOS 12.0.19

Cisco IOS 12.0.1

Cisco IOS 12.0(9)S

Cisco IOS 12.0(8.3)SC

Cisco IOS 12.0(8.0.2)S

Cisco IOS 12.0(8)

Cisco IOS 12.0(7.4)S

Cisco IOS 12.0(7)XK

Cisco IOS 12.0(7)T

Cisco IOS 12.0(7)SC

Cisco IOS 12.0(7)S1

Cisco IOS 12.0(5.1)XP

Cisco IOS 12.0(5)XK

Cisco IOS 12.0(5)T1

Cisco IOS 12.0(5)T

Cisco IOS 12.0(18)S

Cisco IOS 12.0(17)S

Cisco IOS 12.0(17)

Cisco IOS 12.0(16.06)S

Cisco IOS 12.0(16)W5(21)

Cisco IOS 12.0(15)S3

Cisco IOS 12.0(14)W5(20)

Cisco IOS 12.0(14)ST

Cisco IOS 12.0(13)W5(19c)

Cisco IOS 12.0(10)W5(18g)

Cisco IOS 12.0(10)W5

Cisco IOS 12.0 XE

Cisco IOS 12.0 WC

Cisco IOS 12.0 SY

Cisco IOS 12.0 SX

Cisco IOS 12.0 ST

Cisco IOS 12.0 SP

Cisco IOS 12.0 SL

Cisco IOS 12.0 SC

Cisco IOS 12.0 S

Cisco IOS 12.0 (3)

Cisco IOS 12.0 (21)S

Cisco IOS 12.0 (21)S

Cisco IOS 12.0 (21)S

Cisco IOS 12.0 (19)S

Cisco IOS 12.0 (19)S

Cisco IOS 12.0 (19)

Cisco IOS 12.0 (18)S

Cisco IOS 12.0 (17)S

Cisco IOS 12.0

Cisco IOS 11.3XA

Cisco IOS 11.3WA4

Cisco IOS 11.3T

Cisco IOS 11.3NA

Cisco IOS 11.3MA

Cisco IOS 11.3HA

Cisco IOS 11.3DB

Cisco IOS 11.3DA

Cisco IOS 11.3AA

Cisco IOS 11.3.1T

Cisco IOS 11.3.1ED

Cisco IOS 11.3.11b

Cisco IOS 11.3.1

Cisco IOS 11.3(2)XA

Cisco IOS 11.3 (11b)

Cisco IOS 11.3

Cisco IOS 11.2WA3

Cisco IOS 11.2SA

Cisco IOS 11.2P

Cisco IOS 11.2GS

Cisco IOS 11.2F

Cisco IOS 11.2BC

Cisco IOS 11.2.9XA

Cisco IOS 11.2.9P

Cisco IOS 11.2.8SA5

Cisco IOS 11.2.8SA3

Cisco IOS 11.2.8SA1

Cisco IOS 11.2.8P

Cisco IOS 11.2.8

Cisco IOS 11.2.4F1

Cisco IOS 11.2.4F

Cisco IOS 11.2.4

Cisco IOS 11.2.10BC

Cisco IOS 11.2.10

Cisco IOS 11.2(9)XA

Cisco IOS 11.2(4)XAf

Cisco IOS 11.2(4)XA

Cisco IOS 11.2(4)

Cisco IOS 11.2(19)GS0.2

Cisco IOS 11.2(17)

Cisco IOS 11.2 (26a)

Cisco IOS 11.2

Cisco IOS 11.1IA

Cisco IOS 11.1CT

Cisco IOS 11.1CC

Cisco IOS 11.1CA

Cisco IOS 11.1AA

Cisco IOS 11.1.9IA

Cisco IOS 11.1.7CA

Cisco IOS 11.1.7AA

Cisco IOS 11.1.7

Cisco IOS 11.1.17CT

Cisco IOS 11.1.17CC

Cisco IOS 11.1.16IA

Cisco IOS 11.1.16AA

Cisco IOS 11.1.16

Cisco IOS 11.1.15IA

Cisco IOS 11.1.15CA

Cisco IOS 11.1.15AA

Cisco IOS 11.1.15

Cisco IOS 11.1.13IA

Cisco IOS 11.1.13CA

Cisco IOS 11.1.13AA

Cisco IOS 11.1.13

Cisco IOS 11.1(36)CC2

Cisco IOS 11.1 (24a)

Cisco IOS 11.1

具体描述

Cisco IOS是使用广泛的网络操作系统。

构建使用非凡协议字段的IPV4包发送给使用CISCO IOS的接口,就会由于标记输入队列满而停止处理通信,这种攻击不需任何验证,并且IPV4包处理默认打开。

攻击者构建使用协议类型为53 (SWIPE), 55 (IP Mobility), 77 (Sun ND), 或103 (Protocol Independent Multicast - PIM)的包,发送给Cisco IOS设备而停止响应。

不过假如接口配置运行了PIM协议,使用103协议的恶意包将不会对此接口有任何影响。

设备需要手工重新启动清除输入队列。

测试代码

尚无

解决方案

在路由器上通过访问控制列表(ACL)过滤从未授权地址直接发往路由器本身地址的流量。

可以参考Cisco提供的下列文档进行设置:

http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.sHtml#workarounds

http://www.cisco.com/warp/public/707/racl.html

http://www.cisco.com/warp/public/707/iacl.html

Cisco提供了一个样例ACL, 禁止所有协议类型为53,55,77,103的包通过路由器:

Access-list 101 deny 53 any any

access-list 101 deny 55 any any

access-list 101 deny 77 any any

access-list 101 deny 103 any any

!--- insert any other previously applied ACL entries here

!--- you must permit other protocols through to allow normal

!--- traffic -- previously defined permit lists will work

!--- or you may use the permit ip any any shown here

access-list 101 permit ip any any

Cisco IOS 12.3不存在此漏洞,用户可以升级。

 
 
 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
 
 
© 2005- 王朝網路 版權所有 導航