
====================================================================

                                CERT-Renater

                     Note d'Information No. 2016/VULN291
_____________________________________________________________________

DATE                : 11/08/2016

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco ASR 9001 Aggregation Services Routers.

=====================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160810-iosxr
____________________________________________________________________

Cisco Security Advisory: Cisco IOS XR Software for Cisco ASR 9001
Aggregation Services Routers Fragmented Packet Denial of Service
Vulnerability

Advisory ID: cisco-sa-20160810-iosxr

Revision 1.0

For Public Release 2016 August 10 16:00  GMT

+---------------------------------------------------------------------

Summary
=======

A vulnerability in the driver processing functions of Cisco IOS XR
Software for Cisco ASR 9001 Aggregation Services Routers could allow an
unauthenticated, remote attacker to cause a memory leak on the route
processor (RP) of an affected device, which could cause the device to
drop all control-plane protocols and lead to a denial of service
condition (DoS) on a targeted system.

The vulnerability is due to improper handling of crafted, fragmented
packets that are directed to an affected device. An attacker could
exploit this vulnerability by sending crafted, fragmented packets to an
affected device for processing and reassembly. A successful exploit
could allow the attacker to cause a memory leak on the RP of the
device, which could cause the device to drop all control-plane
protocols and eventually lead to a DoS condition on the targeted system.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability. However,
there are mitigations for this vulnerability.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160810-iosxr


==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================





