First published: Fri Sep 26 2008(Updated: )
The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.3xr | |
Cisco IOS | =12.3ya | |
Cisco IOS | =12.3xs | |
Cisco IOS | =12.4xj | |
Cisco IOS | =12.4xt | |
Cisco IOS | =12.3t | |
Cisco IOS | =12.4xf | |
Cisco IOS | =12.4xv | |
Cisco IOS | =12.3yd | |
Cisco IOS | =12.3xl | |
Cisco IOS | =12.3yk | |
Cisco IOS | =12.3yt | |
Cisco IOS | =12.4xk | |
Cisco IOS | =12.3yg | |
Cisco IOS | =12.4xa | |
Cisco IOS | =12.3za | |
Cisco IOS | =12.4xe | |
Cisco IOS | =12.3xq | |
Cisco IOS | =12.3ys | |
Cisco IOS | =12.3yh | |
Cisco IOS | =12.3xx | |
Cisco IOS | =12.4xc | |
Cisco IOS | =12.3yi |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2739 has been classified as a denial of service vulnerability that can result in device crashes or hangs.
To fix CVE-2008-2739, upgrade to a non-vulnerable version of Cisco IOS as specified in Cisco's advisory.
CVE-2008-2739 affects several versions of Cisco IOS, including 12.3 and 12.4 versions as detailed in the advisory.
Yes, CVE-2008-2739 can be exploited remotely through specific network traffic targeting the IPS signature engine.
CVE-2008-2739 can allow attackers to disrupt network services, making devices vulnerable to denial of service conditions.