涉及程序: CISCO IOS 详细: CISCO 发布安全公告,指出其 IOS 存在 D.o.S 漏洞,并建议用户尽快升级到最新版本。 如果扫描器对受影响系统的3100-3999, 5100-5999, 7100-7999, 和 10100-10999 进行 TCP 连接的话,将会导致 Cisco IOS 在这些端口监听的服务停止响应并自动重启。 受影响版本: Cisco IOS software version 12.1(2)T , 12.1(3)T 运行 CISCO IOS 的 CISCO 设备包括: * Cisco routers in the AGS/MGS/CGS/AGS+, IGS, RSM, 8xx, ubr9xx, 1xxx, 25xx, 26xx, 30xx, 36xx, 38xx, 40xx, 45xx, 47xx, AS52xx, * AS53xx, AS58xx, 64xx, 70xx, 72xx (including the ubr72xx), 75xx, and 12xxx series. * Most recent versions of the LS1010 ATM switch. * Some versions of the Catalyst 2900XL LAN switch. * The Cisco DistributedDirector. 没运行 CISCO IOS 的设备(即无此漏洞的设备): * 7xx dialup routers (750, 760, and 770 series) are not affected. * Catalyst 19xx, 28xx, 29xx, 3xxx, and 5xxx LAN switches are not affected, except for some versions of the Catalyst 2900XL. However, optional router modules running Cisco IOS software in switch backplanes, such as the RSM module for the Catalyst 5000 and 5500, are affected. * WAN switching products in the IGX and BPX lines are not affected. * The MGX (formerly known as the AXIS shelf) is not affected. * No host-based software is affected. * The Cisco PIX Firewall is not affected. * The Cisco LocalDirector is not affected. * The Cisco Cache Engine is not affected. * The Cisco CSS 11000 series switch is not affected 解决方案: 如果用户不清楚系统是否运行了 CISCO IOS,请登录进系统后运行显示版本命令,CISCO IOS 将会显示 "IOS" 或 "Internetwork Operating System Software" 信息。 有合同用户访问下面站点能取得补丁: http://www.cisc.com 无合同用户请联系 CISCO 技术支持中心:http://www.cisco.com/warp/public/687/Directory.shtml