exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

MU Security Advisory 2006-10.01

MU Security Advisory 2006-10.01
Posted Oct 20, 2006
Authored by MU Dynamics | Site labs.musecurity.com

Mu Security MU-200610-01: Denial of Service in XORP OSPFv2: OSPF carries link state information using Link State Advertisements. Each LSA contains a length field as well as a checksum. XORP performs a checksum verification when processing an LSA. During the checksum verification, the length field is used to calculate the payload. An invalid length field causes an out of bounds read, causing the OSPF daemon to crash.

tags | advisory, denial of service
SHA-256 | ba8f5f4a3cbb2887f475beee8d4367ae57c087c94175bdd0caae9389252befbd

MU Security Advisory 2006-10.01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Denial of Service in XORP OSPFv2 [MU-200610-01]
October 17, 2006

http://labs.musecurity.com/advisories.html

Affected Product/Versions:

XORP OSPFv2 1.2, 1.3

Product Overview:

"XORP is the eXtensible Open Router Platform.

Our goal is to develop an open source software router platform that is stable
and fully featured enough for production use, and flexible and extensible enough
to enable network research. Currently XORP implements routing protocols for IPv4
and IPv6 and a unified means to configure them."

Vulnerability Details:

OSPF carries link state information using Link State Advertisements. Each
LSA contains a length field as well as a checksum.

XORP performs a checksum verification when processing an LSA. During the
checksum verification, the length field is used to calculate the payload.
An invalid length field causes an out of bounds read, causing the OSPF daemon
to crash.

Vendor Response / Solution:

Apply the relevant patch to your XORP system and follow vendor instructions.

[XORP 1.2]
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.2.patch

[XORP 1.3]
# wget http://www.xorp.org/patches/SA-06:01/xorp_sa_06:01.ospf_1.3.patch

Mu Security would like to thank XORP for timely remediation of this
vulnerability.

History:

10/13/06 - First contact with vendor
10/16/06 - Patch available
10/17/06 - Advisory released

Credit:

This vulnerability was discovered by the Mu Security research team.

http://labs.musecurity.com/pgpkey.txt

Mu Security offers a new class of security analysis system, delivering a
rigorous and streamlined methodology for verifying the robustness and security
readiness of any IP-based product or application. Founded by the pioneers of
intrusion detection and prevention technology, Mu Security is backed by
preeminent venture capital firms that include Accel Partners, Benchmark
Capital and DAG Ventures. The company is headquartered in Sunnyvale, CA. For
more information, visit the company's website at http://www.musecurity.com.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (Darwin)

iD8DBQFFNUJ4Ml+docYeP+YRAroCAJ92uQQMjbdsQhY30snYXmU5oZpiDQCfcXuH
05TaD1EHyE16qFh9ZD1/xyE=
=PBU6
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close