
=====================================================================

                           CERT-Renater

               Note d'Information No. 2013/VULN481
_____________________________________________________________________

DATE                : 24/10/2013

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Cisco IOS XR versions 3.3.0 up to and including
                                            4.2.0.

======================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-iosxr
______________________________________________________________________

Cisco IOS XR Software Route Processor Denial of Service Vulnerability

Advisory ID: cisco-sa-20131023-iosxr

Revision 1.0

For Public Release 2013 October 23 16:00  UTC (GMT)
======================================================================

Summary
- -------

Cisco IOS XR Software contains a vulnerability when handling fragmented
packets that may result in a denial of service condition of the Cisco
CRS Route Processor cards listed under "Affected Products".  The
vulnerability affects IOS XR Software versions 3.3.0 to 4.2.0

The vulnerability is a result of improper handing of fragmented packets
and could cause the route processor, which processes the packets, to be
unable to transmit packets to the fabric.

Customers that are running version 4.2.1 or later of Cisco IOS XR
Software, or that have previously installed the SMU for CSCtz62593 are
not affected by this vulnerability.

Cisco has released free software updates that address these
vulnerabilities.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-iosxr


=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================
