First published: Thu Mar 29 2012(Updated: )
Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | =12.4 | |
Puppet Cisco IOS | =15.0 | |
Puppet Cisco IOS | =15.1 | |
Puppet Cisco IOS | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0387 has a high severity rating as it allows remote attackers to cause a denial of service.
To fix CVE-2012-0387, apply the latest software updates provided by Cisco for affected IOS versions.
CVE-2012-0387 affects Cisco IOS versions 12.4, 15.0, 15.1, and 15.2 with the HTTP Inspection Engine feature.
CVE-2012-0387 enables remote attackers to exploit crafted transit HTTP traffic to cause memory leaks.
Yes, CVE-2012-0387 can lead to device instability by causing memory consumption or complete device reloads.