Thursday, August 9, 2007

Cisco IOS Next Hop Resolution Protocol Buffer Overflow

A vulnerability has been reported in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

The vulnerability is caused due to a boundary error in the implementation of the Next Hop Resolution Protocol. This can be exploited to cause a buffer overflow by sending a specially crafted NHRP packet containing an invalid total length in the fixed header.

Successful exploitation requires that support for the Next Hop Resolution Protocol is enabled.

--------------------

Exploit code is available on Milw0rm - http://www.milw0rm.com/exploits/4272

No comments:

Post a Comment