New User, Welcome!     Login

User Datagram Protocol

Cisco Security Advisory: Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco IOS User Datagram Protocol Delivery
                         Issue For IPv4/IPv6 Dual-stack Routers

Advisory ID: cisco-sa-20080326-IPv4IPv6

http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtml


Malformed DHCPv6 packets cause RPC to become unresponsive

      1 0.000000    fec0:0:beef:f00d::feed fe80::754f:6144:be9e:2ae7 DHCPv6   Reply

Frame 1 (183 bytes on wire, 183 bytes captured)
Ethernet II, Src: 50:48:49:4f:4e:53 (50:48:49:4f:4e:53), Dst: 50:48:49:4f:4e:43 (50:48:49:4f:4e:43)
Internet Protocol Version 6
User Datagram Protocol, Src Port: 547 (547), Dst Port: 546 (546)
DHCPv6
    Message type: Reply (7)
    Transaction-ID: 0x007f1ea5
    Server Identifier
        option type: 2

[TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC

1. Send sequentially (i.e., ALMOST on the same time) the following
protocols:
   - ICMP: Internet Control Message Protocol
   - IGMP: Internet Group Management Protocol
   - TCP:  Transmission Control Protocol
   - UDP:  User Datagram Protocol

2. Send an (quite) incredible amount of packets per second, making it a
“second to none” tool:
   - More than 1,000,000 pps of SYN Flood (+50% of the network’s uplink) in
a 1000BASE-T Network (Gigabit Ethernet).

Cisco Security Advisory: Multiple Vulnerabilities in Firewall Services Module

An FWSM that has the MGCP application layer protocol inspection feature
enabled may reload when a crafted MGCP packet is processed by the
device. MGCP application layer protocol inspection is not enabled by
default.

MGCP messages are transmitted over the User Datagram Protocol (UDP),
which does allow the crafted MGCP messages to be sourced from a spoofed
address. Only the MGCP for gateway application (MGCP traffic on UDP port
2427) is affected.

To determine whether MGCP inspection is configured on the FWSM, log

Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and ASA Appliances

A PIX or ASA security appliance with the Media Gateway Control Protocol
(MGCP) application layer protocol inspection feature enabled may reload
when the device processes a crafted MGCP packet. MGCP application layer
protocol inspection is not enabled by default.

MGCP messages are transmitted over the User Datagram Protocol (UDP),
which does allow the crafted MGCP messages to be sourced from a spoofed
address. Only the MGCP for gateway application (MGCP traffic on UDP port
2427) is affected.

To determine whether MGCP inspection is configured on the PIX or ASA,

Cisco Security Advisory: Cisco IOS Virtual Private Dial-up Network Denial of Service Vulnerability

    http://www.cisco.com/warp/public/707/cisco-sa-20080326-pptp.shtml
   
  * Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-dlsw.shtml
   
  * Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6
    Dual-stack Routers
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtml
   
  * Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor
    32, Supervisor 720, or Route Switch Processor 720

Cisco Security Advisory: Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability

Summary
=======

Cisco 10000, uBR10012 and uBR7200 series devices use a User Datagram
Protocol (UDP) based Inter-Process Communication (IPC) channel that
is externally reachable. An attacker could exploit this vulnerability
to cause a denial of service (DoS) condition on affected devices. No
other platforms are affected.

Cisco has released free software updates that address this

Cisco Security Advisory: Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS

    http://www.cisco.com/warp/public/707/cisco-sa-20080326-pptp.shtml
   
  * Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-dlsw.shtml
   
  * Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6
    Dual-stack Routers
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtml
   
  * Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor
    32, Supervisor 720, or Route Switch Processor 720

Cisco Security Advisory: Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Route Switch Processor 720

    http://www.cisco.com/warp/public/707/cisco-sa-20080326-pptp.shtml
   
  * Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-dlsw.shtml
   
  * Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6
    Dual-stack Routers
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtml

  * Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor
    32, Supervisor 720, or Route Switch Processor 720

Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities

The Mobile IP Support NAT Traversal feature is documented in RFC
3519. It introduces an alternative method for tunneling Mobile IP
data traffic. New extensions in the Mobile IP registration request
and reply messages have been added for establishing User Datagram
Protocol (UDP) tunneling. This feature allows mobile devices in
collocated mode that use a private IP address (RFC 1918) or foreign
agents (FAs) that use a private IP address for the care-of address
(CoA) to establish a tunnel and traverse a NAT-enabled router with
mobile node (MN) data traffic from the home agent (HA).


Cisco Security Advisory: SNMP Version 3 Authentication Vulnerabilities

There are three general types of SNMP operations: "get" requests to
request information, "set" requests that modify the configuration of
a remote device, and "trap" messages that provide a monitoring
function. SNMP requests and traps are transported over User Datagram
Protocol (UDP) and are received at the assigned destination port
numbers 161 and 162, respectively.

SNMPv3 provides secure access to devices by authenticating and
encrypting packets over the network. RFC2574 defines
the use of HMAC-MD5-96 and HMAC-SHA-96 as the possible authentication

Cisco Security Advisory: Cisco IOS Multicast Virtual Private Network (MVPN) Data Leak

    http://www.cisco.com/warp/public/707/cisco-sa-20080326-pptp.shtml

  * Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-dlsw.shtml

  * Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6
    Dual-stack Routers
    http://www.cisco.com/warp/public/707/cisco-sa-20080326-IPv4IPv6.shtml

  * Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor
    32, Supervisor 720, or Route Switch Processor 720



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!