The Register® — Biting the hand that feeds IT

Cisco protects routers against 'Black Hat' bug

Double plus bad

Free whitepaper – Deploying high-density zones in a low-density data center

Cisco has warned users of a flaw in its IOS (Internetwork Operating System) software which might be used by hackers to bypass security restrictions and run hostile code on network devices. The vulnerability reportedly affects all Cisco products that run Cisco IOS software, including routers and a limited range of switches that don't run CatOS. The networking giant has released fixes for the 12.x releases of its software as explained in a patching matrix here.

The security flap stems from a heap-based buffer overflow security bug involving internal operating system timers. This might be exploited in conjunction with some other heap-based buffer overflow vulnerability to run hostile code on vulnerable systems.

In a statement, Cisco said it had not received any reports about active exploitation of the vulnerability. It explained that the security flaw was related to security bugs outlined in a presentation by security researcher Michael Lynn at Black Hat in July. This presentation became a cause celebre in the security research community after Cisco controversially obtained a restraining order to suppress publication of Lynn's findings.

"This advisory documents changes to Cisco IOS as a result of continued research related to the demonstration of the exploit for another vulnerability which occurred in July 2005 at the Black Hat USA Conference. Cisco addressed the IPv6 attack vector used in that demonstration in a separate advisory published on 29 July 2005," it said. ®

Free whitepaper – Fundamental Principles of Air Conditioners for Information Technology

Don’t Miss

ToshibaToshiba plans new enterprise: High capacity 3.5-inch HDDs

Wants to be a bigger player in the big drive market

IBMIBM greases mainframe app pipe

System zware boost

acer logoAcer, Asus dominate Euro netbook biz

Canalys Mobility Forum Demand rises despite recession

Quantum logos 75x75Quantum's small tape libraries get big

At least a little