信息提供: | 安全公告(或线索)提供热线:51cto.editor@gmail.com |
漏洞类别: | 溢出错误 |
攻击类型: | 本地越权访问 |
发布日期: | 2003-07-31 |
更新日期: | 2003-08-13 |
受影响系统: | Cisco IOS 12.2YH Cisco IOS 12.2YG Cisco IOS 12.2YF Cisco IOS 12.2YD Cisco IOS 12.2YC Cisco IOS 12.2YB Cisco IOS 12.2YA Cisco IOS 12.2XW Cisco IOS 12.2XT Cisco IOS 12.2XS Cisco IOS 12.2XR Cisco IOS 12.2XQ Cisco IOS 12.2XK Cisco IOS 12.2XJ Cisco IOS 12.2XI Cisco IOS 12.2XH Cisco IOS 12.2XG Cisco IOS 12.2XF Cisco IOS 12.2XE Cisco IOS 12.2XD Cisco IOS 12.2XC Cisco IOS 12.2XB Cisco IOS 12.2XA Cisco IOS 12.2T Cisco IOS 12.2DD Cisco IOS 12.2BC Cisco IOS 12.2(3) Cisco IOS 12.2(2.2)T Cisco IOS 12.2(2)XA Cisco IOS 12.2(1b) Cisco IOS 12.2(11)T Cisco IOS 12.2(1.1) Cisco IOS 12.2(1)XQ Cisco IOS 12.2(1)XH Cisco IOS 12.2(1)XD1 Cisco IOS 12.2(1) Cisco IOS 12.2 YH Cisco IOS 12.2 YG Cisco IOS 12.2 YF Cisco IOS 12.2 YC Cisco IOS 12.2 YB Cisco IOS 12.2 YA Cisco IOS 12.2 XM Cisco IOS 12.2 XL Cisco IOS 12.2 XK Cisco IOS 12.2 XJ Cisco IOS 12.2 XI Cisco IOS 12.2 XH Cisco IOS 12.2 XE Cisco IOS 12.2 XD Cisco IOS 12.2 XC Cisco IOS 12.2 S Cisco IOS 12.2 MB Cisco IOS 12.2 DA Cisco IOS 12.2 BZ Cisco IOS 12.2 BY Cisco IOS 12.2 BC Cisco IOS 12.2 (7a) Cisco IOS 12.2 (7)DA Cisco IOS 12.2 (7) Cisco IOS 12.2 (5) Cisco IOS 12.2 (4)B Cisco IOS 12.2 (13.03)B Cisco IOS 12.2 (12.05)T Cisco IOS 12.2 (12.05)S Cisco IOS 12.2 (12.05) Cisco IOS 12.2 (12.02)T Cisco IOS 12.2 (12.02)S Cisco IOS 12.2 Cisco IOS 12.2 Cisco IOS 12.1YH Cisco IOS 12.1YF Cisco IOS 12.1YE Cisco IOS 12.1YD Cisco IOS 12.1YC Cisco IOS 12.1YB Cisco IOS 12.1YA Cisco IOS 12.1XZ Cisco IOS 12.1XY Cisco IOS 12.1XX Cisco IOS 12.1XW Cisco IOS 12.1XV Cisco IOS 12.1XU Cisco IOS 12.1XT Cisco IOS 12.1XS Cisco IOS 12.1XR Cisco IOS 12.1XQ Cisco IOS 12.1XP Cisco IOS 12.1XM Cisco IOS 12.1XL Cisco IOS 12.1XK Cisco IOS 12.1XJ Cisco IOS 12.1XI Cisco IOS 12.1XH Cisco IOS 12.1XG Cisco IOS 12.1XF Cisco IOS 12.1XE Cisco IOS 12.1XD Cisco IOS 12.1XC Cisco IOS 12.1XB Cisco IOS 12.1XA Cisco IOS 12.1T Cisco IOS 12.1EZ Cisco IOS 12.1EY Cisco IOS 12.1EX Cisco IOS 12.1EC Cisco IOS 12.1EA Cisco IOS 12.1E Cisco IOS 12.1DC Cisco IOS 12.1DB Cisco IOS 12.1DA Cisco IOS 12.1CX Cisco IOS 12.1AA Cisco IOS 12.10S Cisco IOS 12.1(9)E Cisco IOS 12.1(8a)E Cisco IOS 12.1(8)E Cisco IOS 12.1(8) Cisco IOS 12.1(7) Cisco IOS 12.1(6.5)EC3 Cisco IOS 12.1(6)EZ1 Cisco IOS 12.1(6)EY Cisco IOS 12.1(5)YF2 Cisco IOS 12.1(5)YD2 Cisco IOS 12.1(5)YC1 Cisco IOS 12.1(5)YB4 Cisco IOS 12.1(5)XY6 Cisco IOS 12.1(5)XV3 Cisco IOS 12.1(5)XU1 Cisco IOS 12.1(5)XS Cisco IOS 12.1(5)XR2 Cisco IOS 12.1(5)XG5 Cisco IOS 12.1(5)T Cisco IOS 12.1(5)DC Cisco IOS 12.1(5)DB1 Cisco IOS 12.1(5)DA1 Cisco IOS 12.1(4.3)T Cisco IOS 12.1(4)XM4 Cisco IOS 12.1(4)DC Cisco IOS 12.1(4)DB1 Cisco IOS 12.1(4)DB Cisco IOS 12.1(4) Cisco IOS 12.1(3)XT3 Cisco IOS 12.1(3)XP4 Cisco IOS 12.1(2)E1 Cisco IOS 12.1(1a)T1 Cisco IOS 12.1(13.4)E Cisco IOS 12.1(12)E Cisco IOS 12.1(11)E Cisco IOS 12.1(10)E Cisco IOS 12.1(1.3)T Cisco IOS 12.1 YC Cisco IOS 12.1 YB Cisco IOS 12.1 XG Cisco IOS 12.1 XF Cisco IOS 12.1 EY Cisco IOS 12.1 EX Cisco IOS 12.1 EW Cisco IOS 12.1 EC Cisco IOS 12.1 EA Cisco IOS 12.1 E Cisco IOS 12.1 (12b) Cisco IOS 12.1 (11b) Cisco IOS 12.1 (11) Cisco IOS 12.1 (11) Cisco IOS 12.1 (10a) Cisco IOS 12.1 (10)E Cisco IOS 12.1 (10)E Cisco IOS 12.1 (10)E Cisco IOS 12.1 Cisco IOS 12.1 Cisco IOS 12.0XW Cisco IOS 12.0XV Cisco IOS 12.0XU Cisco IOS 12.0XS Cisco IOS 12.0XR Cisco IOS 12.0XQ Cisco IOS 12.0XP Cisco IOS 12.0XN Cisco IOS 12.0XM Cisco IOS 12.0XL Cisco IOS 12.0XK Cisco IOS 12.0XJ Cisco IOS 12.0XI Cisco IOS 12.0XH Cisco IOS 12.0XG Cisco IOS 12.0XF Cisco IOS 12.0XE Cisco IOS 12.0XD Cisco IOS 12.0XC Cisco IOS 12.0XB Cisco IOS 12.0XA Cisco IOS 12.0WT Cisco IOS 12.0WC Cisco IOS 12.0W5 Cisco IOS 12.0T Cisco IOS 12.0SX Cisco IOS 12.0ST Cisco IOS 12.0SP Cisco IOS 12.0SL Cisco IOS 12.0SC Cisco IOS 12.0S Cisco IOS 12.0DC Cisco IOS 12.0DB Cisco IOS 12.0DA Cisco IOS 12.0.7(T) Cisco IOS 12.0.7 Cisco IOS 12.0.6 Cisco IOS 12.0.5 Cisco IOS 12.0.4T Cisco IOS 12.0.4S Cisco IOS 12.0.4 Cisco IOS 12.0.3T2 Cisco IOS 12.0.3 Cisco IOS 12.0.2XG Cisco IOS 12.0.2XF Cisco IOS 12.0.2XD Cisco IOS 12.0.2XC Cisco IOS 12.0.2 Cisco IOS 12.0.1XE Cisco IOS 12.0.1XB Cisco IOS 12.0.1XA3 Cisco IOS 12.0.1W Cisco IOS 12.0.19 Cisco IOS 12.0.1 Cisco IOS 12.0(9)S Cisco IOS 12.0(8.3)SC Cisco IOS 12.0(8.0.2)S Cisco IOS 12.0(8) Cisco IOS 12.0(7.4)S Cisco IOS 12.0(7)XK Cisco IOS 12.0(7)T Cisco IOS 12.0(7)SC Cisco IOS 12.0(7)S1 Cisco IOS 12.0(5.1)XP Cisco IOS 12.0(5)XK Cisco IOS 12.0(5)T1 Cisco IOS 12.0(5)T Cisco IOS 12.0(18)S Cisco IOS 12.0(17)S Cisco IOS 12.0(17) Cisco IOS 12.0(16.06)S Cisco IOS 12.0(16)W5(21) Cisco IOS 12.0(15)S3 Cisco IOS 12.0(14)W5(20) Cisco IOS 12.0(14)ST Cisco IOS 12.0(13)W5(19c) Cisco IOS 12.0(10)W5(18g) Cisco IOS 12.0(10)W5 Cisco IOS 12.0 XE Cisco IOS 12.0 WC Cisco IOS 12.0 SY Cisco IOS 12.0 SX Cisco IOS 12.0 ST Cisco IOS 12.0 SP Cisco IOS 12.0 SL Cisco IOS 12.0 SC Cisco IOS 12.0 S Cisco IOS 12.0 (3) Cisco IOS 12.0 (21)S Cisco IOS 12.0 (21)S Cisco IOS 12.0 (21)S Cisco IOS 12.0 (19)S Cisco IOS 12.0 (19)S Cisco IOS 12.0 (19) Cisco IOS 12.0 (18)S Cisco IOS 12.0 (17)S Cisco IOS 12.0 Cisco IOS 11.3XA Cisco IOS 11.3WA4 Cisco IOS 11.3T Cisco IOS 11.3NA Cisco IOS 11.3MA Cisco IOS 11.3HA Cisco IOS 11.3DB Cisco IOS 11.3DA Cisco IOS 11.3AA Cisco IOS 11.3.1T Cisco IOS 11.3.1ED Cisco IOS 11.3.11b Cisco IOS 11.3.1 Cisco IOS 11.3(2)XA Cisco IOS 11.3 (11b) Cisco IOS 11.3 Cisco IOS 11.2WA3 Cisco IOS 11.2SA Cisco IOS 11.2P Cisco IOS 11.2GS Cisco IOS 11.2F Cisco IOS 11.2BC Cisco IOS 11.2.9XA Cisco IOS 11.2.9P Cisco IOS 11.2.8SA5 Cisco IOS 11.2.8SA3 Cisco IOS 11.2.8SA1 Cisco IOS 11.2.8P Cisco IOS 11.2.8 Cisco IOS 11.2.4F1 Cisco IOS 11.2.4F Cisco IOS 11.2.4 Cisco IOS 11.2.10BC Cisco IOS 11.2.10 Cisco IOS 11.2(9)XA Cisco IOS 11.2(4)XAf Cisco IOS 11.2(4)XA Cisco IOS 11.2(4) Cisco IOS 11.2(19)GS0.2 Cisco IOS 11.2(17) Cisco IOS 11.2 (26a) Cisco IOS 11.2 Cisco IOS 11.1IA Cisco IOS 11.1CT Cisco IOS 11.1CC Cisco IOS 11.1CA Cisco IOS 11.1AA Cisco IOS 11.1.9IA Cisco IOS 11.1.7CA Cisco IOS 11.1.7AA Cisco IOS 11.1.7 Cisco IOS 11.1.17CT Cisco IOS 11.1.17CC Cisco IOS 11.1.16IA Cisco IOS 11.1.16AA Cisco IOS 11.1.16 Cisco IOS 11.1.15IA Cisco IOS 11.1.15CA Cisco IOS 11.1.15AA Cisco IOS 11.1.15 Cisco IOS 11.1.13IA Cisco IOS 11.1.13CA Cisco IOS 11.1.13AA Cisco IOS 11.1.13 Cisco IOS 11.1(36)CC2 Cisco IOS 11.1 (24a) Cisco IOS 11.1 Cisco IOS 11.0x Cisco IOS 11.0.x Cisco IOS 11.0.20.3 Cisco IOS 11.0.17BT Cisco IOS 11.0.17 Cisco IOS 11.0.12(a)BT Cisco IOS 11.0.12 Cisco IOS 11.0 (22a) Cisco IOS 11.0 (18) Cisco IOS 11.0 Cisco IOS 10.3.4.3 Cisco IOS 10.3.4.2 Cisco IOS 10.3.3.4 Cisco IOS 10.3.3.3 Cisco IOS 10.3.19a Cisco IOS 10.3.16 Cisco IOS 10.3 |
安全系统: | Cisco IOS 12.3T |
漏洞报告人: | FX (fx@phenoelit.de) |
漏洞描述: | BUGTRAQ ID: 8373 CVE(CAN) ID: CVE-2003-0647 Cisco IOS是部署非常广泛的网络操作系统。很多Cisco设备都运行IOS。 Cisco IOS设备的HTTP服务程序没有正确处理超大数据请求,远程攻击者可以利用这个漏洞对服务进行缓冲区溢出攻击,可能以系统权限在设备上运行任意指令。 如果CISCO IOS开启了http服务,攻击者发送特殊构建的包含2Gb的数据的HTTP GET请求,可导致触发缓冲区溢出,造成设备重起,或者存在以系统权限执行任意指令的可能。 |
测试方法: | 无 |
解决方法: | 临时解决方法: 如果您不能立刻安装补丁或者升级,NSFOCUS建议您采取以下措施以降低威胁: * CISCO提供了如下示例ACL规则: ip http access-class access-list access-list ..... access-list 或者关闭HTTP服务程序。 厂商补丁: Cisco ----- 如下CISCO IOS固件版本不存在此漏洞: Cisco IOS 12.3T Cisco IOS 12.2(18.2) Cisco IOS 12.2(15)T Cisco IOS 12.2(11)JA1 Cisco IOS 12.0(25.4)S1 Cisco IOS 12.3 (1a) Cisco IOS 12.3 您可以从Cisco网站的软件中心下载升级程序: http://www.cisco.com/tacpage/sw-center/sw-ios.shtml |
|
|||
| · OSPF路由协议专栏 · 思科路由器产品 · 华为路由器产品 · 路由器模拟器 · AIX操作系统管理应用(.. · 思科路由器配置 · 路由器组网解决方案 · 路由器密码恢复 |
· 无线路由器故障处理 · 路由故障处理手册 · 路由器访问控制列表(AC.. · 路由器的安全配置与安.. · 无线路由器配置 · 路由器技巧 · 华为路由器配置 · 路由器配置基础 |
||
|
|||
| · Java基础教程 · VPN技术 · SQL Server 2005全解 · ARP攻击防范与解决方案 · SOA 面向服务架构 · SQL Server 2005全解 · Java编程开发手册 · 三层交换技术专题 |
· SQL Server入门到精通 · Windows Server 2003企.. · Windows远程桌面应用 · C#技术开发指南 · VPN技术 · Solaris 10 配置管理 · C#技术开发指南 · Windows操作系统安装 |
||
|
|||
| · VPN技术 · ARP攻击防范与解决方案 · SQL Server 2005全解 · Java基础教程 · SQL Server入门到精通 · SQL Server 2005全解 · SOA 面向服务架构 · Java编程开发手册 |
· C#技术开发指南 · 三层交换技术专题 · C#技术开发指南 · Windows远程桌面应用 · Windows Server 2003企.. · 邮件服务器专题 · wimax技术与趋势 · Windows操作系统安装 |
||
| ·DB2 Viper快速入门 ·DB2 9数据库的镜像分割与.. |
·将XML应用程序从DB2 8.x.. ·DB2 9中的pureXML:如何.. |
| ·服务器中的“傻瓜机”在.. ·盖茨也喜欢登录Youtube看.. |
· · |
| · 职场冲浪(之八):让感.. ·职场冲浪(之七):潜心.. |
·人生如鞋 ·职场冲浪(之六):从离梦最.. |
| ·将职业教育职业化 - 各IT.. ·思科交换机上实现MAC地址.. |
·关于51CTO合作出书中的职.. ·OSPF动态路由协议入门简介 |
| · NGN:下一代网络 · 网络访问中断大排查 · FTTx光纤接入 |
· 平凡黑客讲述精彩人生(.. · 平凡黑客讲述精彩人生(.. · 平凡黑客讲述精彩人生(.. |
| · C++是垃圾语言?! · 2007年IT界七大抄袭事件 · Java实用开发全集 |
· 解析Ajax开发框架 走进A.. · 基于Google Maps与Ajax.. · 基于Google Maps与Ajax.. |
| · Ubuntu 中文开源频道 · Solaris基础知识入门 · 微软正式发布英文版Wind.. |
· 服务器基础知识入门 · Rambus第二?看全缓冲内.. · 服务器节能对比测试:AM.. |
| · 甲骨文Oracle 11g正式发.. · Oracle数据库开发之PL/S.. · Oracle数据库开发基础教.. |
· 存储2006,一个并购的大.. · IDC宣布浪潮蝉联存储市.. · 双机热备技术 |