Cisco IOS WAAS和MACE多个远程拒绝服务漏洞
发布日期:2012-03-28
更新日期:2012-03-29
受影响系统:
Cisco IOS 15.x
不受影响系统:
Cisco IOS 15.2(3)T
Cisco IOS 15.2(2)T1
Cisco IOS 15.2(1)T2
Cisco IOS 15.2(1)GC2
Cisco IOS 15.1(4)M4
Cisco IOS 15.1(3)T3
Cisco IOS 15.1(2)GC2
Cisco IOS 15.1(2)EY2
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 52751
CVE ID: CVE-2012-1312,CVE-2012-1314
Cisco的网际操作系统(IOS)是一个为网际互连优化的复杂操作系统。Cisco Wide Area Application Services (WAAS) Express功能可优化访问集中放置应用所需的WAN带宽。Cisco Measurement, Aggregation, and Correlation Engine (MACE)是用于测量和分析网络报文的功能。
Cisco IOS软件的WAAS和MACE功能在实现上存在安全漏洞,可允许远程未验证攻击者造成受影响设备重载或泄漏内存。
建议:
--------------------------------------------------------------------------------
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20120328-mace#iosxe)以及相应补丁:
cisco-sa-20120328-mace#iosxe:Multiple Vulnerabilities in Cisco IOS Software Traffic Optimization Features
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-mace#iosxe