jim_duffy
Managing Editor

Tough week for Cisco bugs

Opinion
Feb 3, 20053 mins

* Also: Juniper discovers JUNOS vulnerability; what SBC gets for its $16 billion

It’s Bug of the Week week at Cisco. The company last week warned of three separate IOS software flaws related to BGP, MPLS and IPv6. Two of the three bugs present the opportunity for an outside attacker to send a specially crafted packet, which would disrupt the router and cause it to reload. Attackers could use this technique repeatedly to mount a denial-of-service attack on the router. Cisco has updated software available to fix the IOS problems. The company says it has no reports of any of the three bugs being used in an attack. The week before last, Cisco reported an IOS software glitch could leave VoIP-enabled routers vulnerable to attack. http://www.nwfusion.com/news/2005/0127ios.html

It’s Bug of the Week week at Cisco. The company last week warned of three separate IOS software flaws related to BGP, MPLS and IPv6. Two of the three bugs present the opportunity for an outside attacker to send a specially crafted packet, which would disrupt the router and cause it to reload. Attackers could use this technique repeatedly to mount a denial-of-service attack on the router. Cisco has updated software available to fix the IOS problems. The company says it has no reports of any of the three bugs being used in an attack. The week before last, Cisco reported an IOS software glitch could leave VoIP-enabled routers vulnerable to attack.

https://www.nwfusion.com/news/2005/0127ios.html

Cisco is not the only one with buggy routing software. Juniper is telling all M- and T-Series router customers running releases of JUNOS software developed prior to Jan. 7, 2005, to upgrade the software or suffer a “serious security vulnerability.” The vulnerability could be exploited either by a directly-attached neighboring device or by a remote attacker that can deliver certain packets to the router, according to a Juniper Technical Bulletin obtained by Network World. Routers running vulnerable JUNOS software are susceptible regardless of the router’s configuration, and it is not possible to use firewall filters to protect vulnerable routers, the bulletin states. Juniper says it has modified JUNOS software to address the vulnerability. All versions of JUNOS software built on or after Jan. 22, 2005, contain the modified code, the bulletin states, while software built between Jan. 7 and Jan. 22 may contain the modified code, depending on the specific JUNOS release.

https://www.nwfusion.com/edge/news/2005/0127juniper.html

It’s alright Ma Bell… SBC scooped up AT&T for $16 billion, creating the nation’s largest telecommunications carrier and ending a 100+-year era for another. The deal gives SBC national and international reach, as well as a cache of high-profile enterprise and government accounts. It also gives SBC AT&T’s baggage: AT&T’s business market revenue continues to fall – 15% in 2004, and expectations of a 13% drop in 2005 and 14% in 2006 – as pricing pressures continue and RBOCs take share in the small-business segment, according to UBS Warburg.

https://www.nwfusion.com/edge/news/2005/0127reporsbci.html