nanog mailing list archives

Re: Patching for Cisco vulnerability


From: "Petri Helenius" <pete () he iki fi>
Date: Fri, 18 Jul 2003 23:03:59 +0300



if  (ifc->in_bps > ifc->phy_speed || ifc->out_bps > ifc->phy_speed)
{
crash_router();
}

If they added this code, they'd find these bugs in their
labs instead of in our networks.

I remember seeing an article claiming that Cisco´s automated regression
testing does "more than 250000" tests before they release a piece of code.

However, questions about the nature of these tests and if any tests sent
more traffic than a random scripted ping went unanswered.

Pete


Current thread: