mailing list archives
From: noreply () musecurity com
Date: Wed, 18 Oct 2006 00:07:15 +0100 (BST)
-----BEGIN PGP SIGNED MESSAGE-----
Denial of Service in XORP OSPFv2 [MU-200610-01]
October 17, 2006
XORP OSPFv2 1.2, 1.3
"XORP is the eXtensible Open Router Platform.
Our goal is to develop an open source software router platform that is stable
and fully featured enough for production use, and flexible and extensible enough
to enable network research. Currently XORP implements routing protocols for IPv4
and IPv6 and a unified means to configure them."
OSPF carries link state information using Link State Advertisements. Each
LSA contains a length field as well as a checksum.
XORP performs a checksum verification when processing an LSA. During the
checksum verification, the length field is used to calculate the payload.
An invalid length field causes an out of bounds read, causing the OSPF daemon
Vendor Response / Solution:
Apply the relevant patch to your XORP system and follow vendor instructions.
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.2.patch
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.3.patch
Mu Security would like to thank XORP for timely remediation of this
10/13/06 - First contact with vendor
10/16/06 - Patch available
10/17/06 - Advisory released
This vulnerability was discovered by the Mu Security research team.
Mu Security offers a new class of security analysis system, delivering a
rigorous and streamlined methodology for verifying the robustness and security
readiness of any IP-based product or application. Founded by the pioneers of
intrusion detection and prevention technology, Mu Security is backed by
preeminent venture capital firms that include Accel Partners, Benchmark
Capital and DAG Ventures. The company is headquartered in Sunnyvale, CA. For
more information, visit the company's website at http://www.musecurity.com.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (Darwin)
-----END PGP SIGNATURE-----
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- (no subject) Yoshiaki Nakanishi (Oct 02)
- <Possible follow-ups>
- (no subject) noreply (Oct 17)