Vulnerability Development mailing list archives

Cisco 677 IPOPT_RR internal crash?


From: Vladimir Kraljevich <vlaad () EMPRESARIUM COM>
Date: Mon, 14 Aug 2000 18:42:54 -0000

From my experience, it is possible to block Cisco 677 with 
ICMP echo request in which IPOPT_RR is set. It is not clear 
what is the cause of crash, but it seems to me that 677 is 
unable to properly handle ICMP echo response. If my 
observation is true, it is important, because one can 
easily assemble ICMP echo *response* and send it to Cisco 
677. Notice also that Cisco 677 is generating wrong 
checksum value in direct response to ICMP echo (TTL=1, 
Cisco should answer).

(from command line type:)

ping -r 9 216.32.74.55

After 677 is dead on this way, only hard reset can help.

Please confirm this.


Current thread: