mailing list archives
Cisco Security Advisory: Cisco IOS XR Software Route Processor Denial of Service Vulnerability
From: Cisco Systems Product Security Incident Response Team <psirt () cisco com>
Date: Wed, 23 Oct 2013 12:14:03 -0400
-----BEGIN PGP SIGNED MESSAGE-----
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Advisory ID: cisco-sa-20131023-iosxr
For Public Release 2013 October 23 16:00 UTC (GMT)
Cisco IOS XR Software contains a vulnerability when handling fragmented packets that may result in a denial of service
condition of the Cisco CRS Route Processor cards listed under "Affected Products". The vulnerability affects IOS XR
Software versions 3.3.0 to 4.2.0
The vulnerability is a result of improper handing of fragmented packets and could cause the route processor, which
processes the packets, to be unable to transmit packets to the fabric.
Customers that are running version 4.2.1 or later of Cisco IOS XR Software, or that have previously installed the SMU
for CSCtz62593 are not affected by this vulnerability.
Cisco has released free software updates that address these vulnerabilities.
This advisory is available at the following link:
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools - http://gpgtools.org
-----END PGP SIGNATURE-----
- Cisco Security Advisory: Cisco IOS XR Software Route Processor Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team (Oct 23)