CVE-2009-1154: Buffer Overflow
Published Aug 21, 2009
·Updated
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
Affected Software
19 affected components
Cisco IOS XR=3.6.1
Cisco IOS XR=3.6.2
Cisco IOS XR=3.4.0
Cisco IOS XR=3.5.2
Cisco IOS XR=3.5
Cisco IOS XR=3.4.2
Cisco IOS XR=3.7.2
Cisco IOS XR=3.4
Cisco IOS XR=3.4.1
Cisco IOS XR=3.7.0
Cisco IOS XR=3.4.3
Cisco IOS XR<=3.8.1
Cisco IOS XR=3.6.0
Cisco IOS XR=3.7.1
Cisco IOS XR=3.5.3
Cisco IOS XR=3.7.3
Cisco IOS XR=3.6.3
Cisco IOS XR=3.8.0
Cisco IOS XR=3.5.4
Remediation
Event History
Aug 21, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1154?
The severity of CVE-2009-1154 is considered high due to its potential impact on availability.
2
How do I fix CVE-2009-1154?
To fix CVE-2009-1154, upgrade Cisco IOS XR to version 3.8.2 or later to prevent the denial of service.
3
What systems are affected by CVE-2009-1154?
CVE-2009-1154 affects multiple versions of Cisco IOS XR, specifically versions up to and including 3.8.1.
4
What type of vulnerability is CVE-2009-1154?
CVE-2009-1154 is a denial of service vulnerability resulting from improperly handling long BGP UPDATE messages.
5
Can CVE-2009-1154 be exploited remotely?
Yes, CVE-2009-1154 can be exploited remotely by sending specially crafted BGP UPDATE messages.