You are here: silicon.com > Software > Security Strategy

Security Strategy

Cisco patches critical flaw

...after struggle to keep it under wraps...

By Joris Evers

Published: 3 November 2005 08:35 GMT

Cisco has patched a flaw in the software used to run its routers and switches, in the latest twist in the company's dispute with a security researcher.

The networking giant on Wednesday released an update to fix a serious so-called heap-overflow vulnerability in its Internetwork Operating System, or IOS. This type of security flaw is commonly found in software and often allows a remote attacker to gain control of the affected system. In this case, that would mean control over a Cisco router or switch, which make up the infrastructure of many computer networks, including the Internet.

The newly disclosed flaw in IOS was part of a controversial presentation at the Black Hat security confab in July, but Cisco has been able to keep it under wraps until now.

At Black Hat, security researcher Michael Lynn demonstrated how he could gain control over a router by exploiting security flaws. A widespread attack could seriously disrupt or shut down parts of the internet or a corporate network, he said. IOS had been perceived as impervious to such attacks and Cisco fought Lynn's disclosure by going to court.

A Cisco spokesman said: "Through the IPv6 vulnerability disclosed in July, he was able to achieve a heap-overflow attack on system timers." That flaw, which Cisco provided a fix for in April, was Lynn's way to trigger the heap overflow and commandeer the router.

Cisco in July published details on the IPv6 vulnerability that Lynn exploited in his demonstration, but did not disclose the second, more serious, flaw involved in the attack demonstration until Wednesday. The heap overflow is the actual vulnerability that could let an attacker take over a Cisco router or switch.

The scope of the second flaw explains why Cisco went through great lengths to keep it under wraps, said Johannes Ullrich, chief research officer at the SANS Institute. "These serious flaws show why it was so important for Cisco to hold back on the release at Black Hat," he said. "Early, widespread knowledge of this flaw would have been bad."

Users should update as soon as possible, Ullrich said. This can be a tough task, especially at internet service providers and organisations that run customised configurations. "Too many times in the past, network operators got burned by bad patches and routers not rebooting correctly. It will take a while to have all this worked out," he said.

Joris Evers writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH)

You must have previous experience in a dedicated vulnerability management function where you have been responsible for all potential attacks on a ...

SAP Tester - Registration and Loss

My client, a large complex utilities organisation based in South East, have an immediate requirement for a SAP Tester - registration and loss - to ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

Basic awareness of computer based vulnerability analysis testing. Moderate awareness of computer based vulnerability analysis testing. Basic ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: