[Full-disclosure] Cisco Router IOS History Bug

From: Oliver Pinson-Roxburgh (OPinson-Roxburgh_at_getech.co.uk)
Date: 06/30/05

  • Next message: Joxean Koret: "Re: [Full-disclosure] Publishing exploit code - what is it good for"
    Date: Thu, 30 Jun 2005 17:33:55 +0100
    To: <full-disclosure@lists.grok.org.uk>
    
    
    

    I have been running some scans on some of our Cisco kit and one of our
    scanners came up with the following vulnerability :

    Cisco Router IOS History Bug
    CVE ID:CVE-2000-0368
    Vendor Reference:CSCdk43920

    I would like to clarify this vulnerability by hand if possible. Does any
    one have any way of hand craft testing this vulnerability? A POC or any
    other information on this?
     
     

    --------------------------------------------------------------------------------
    This electronic message contains information from Getech Limited,
    which may be privileged and confidential. The information is intended
    to be for the use of the individual(s) or entity named above. If you
    are not the intended recipient, be aware that any disclosure, copying,
    distribution or use of the contents of this information is prohibited.
    If you have received this electronic message in error, please notify
    me immediately. Opinions, conclusions and other information in this
    message that do not relate to the official business of Getech Limited
    shall be understood as neither given nor endorsed by Getech Limited.

    Getech filters & monitors all Internet communications.
    --------------------------------------------------------------------------------

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Joxean Koret: "Re: [Full-disclosure] Publishing exploit code - what is it good for"

    Relevant Pages

    • RE: QualysGuard - VA/PT appliance
      ... I had an opportunity to review the product at the InfoSec show in Orlando ... or anything much more technical or very in-depth such as their vulnerability ... intended recipient, please contact the sender. ... Subject: QualysGuard - VA/PT appliance ...
      (Pen-Test)
    • RE: Vulnerability to cache poisoning -- the rest of the solution
      ... Vulnerability to cache poisoning -- the rest of the solution ... We were only allowing port 53 outside the firewall (confirmed by the ... If you are not the intended recipient, any disclosure, ...
      (comp.protocols.dns.bind)
    • RE: computer/vulnerability database
      ... Subject: computer/vulnerability database ... able to generate a report for each vulnerability. ... you are not the intended recipient, you may not use, copy or disclose to ... delete this e-mail message. ...
      (Pen-Test)
    • Request for Information on Exploit Novell eDirectory evtFilteredMonitorEventsRequest() function Buff
      ... I could not find any working Poc for this particular vulnerability. ... Please help me out with any information about any working exploit for this vulnerability or Poc. ... Novell eDirectory evtFilteredMonitorEventsRequest() function Buffer Overflow vulnerability ... If you are not the intended recipient, please immediately notify the sender by reply email and destroy all copies of the original message. ...
      (Pen-Test)
    • Request for Information on Exploit Novell eDirectory evtFilteredMonitorEventsRequest() function Buff
      ... I could not find any working Poc for this particular vulnerability. ... Please help me out with any information about any working exploit for this vulnerability or Poc. ... Novell eDirectory evtFilteredMonitorEventsRequest() function Buffer Overflow vulnerability ... If you are not the intended recipient, please immediately notify the sender by reply email and destroy all copies of the original message. ...
      (Focus-IDS)