Home > Security News > IBM and Cisco battle remote attack vulnerabilities
Security News:
EMAIL THIS

IBM and Cisco battle remote attack vulnerabilities

By Edmund X. DeJesus, Contributing Writer
12 Apr 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Both IBM and Cisco are warning of vulnerabilities that remote attackers could exploit to cause denial of service and other problems. Administrators should apply available fixes to avoid security exposure.

IBM's HTTP Server is the latest victim of vulnerabilities due to OpenSSL flaws reported in November 2003. OpenSSL has flaws in handling invalid ASN.1 encodings that a remote attacker may leverage by using unusual ASN.1 tag values. The resulting deallocation of memory can allow denial of service and possible execution of arbitrary code.

The problem affects IBM HTTP Server versions 1.x and 2.x. IBM has provided fixes in the form of upgrades to version 1.3.x or 2.0.

A different vulnerability affects Cisco's Catalyst 6500 Series Switches and 7600 Series Internet Routers using the IP Security (IPSec) VPN Services Module (VPNSM). The VPNSM is a high-speed component that supplies infrastructure-integrated IPSec VPN services. Remote attackers using specially crafted Internet Key Exchange (IKE) packets can force the hardware to crash and reload, causing a denial of service.

The problem affects Cisco IOS versions 12.2SXA, 12.2SXB and 12.2SY using VPNSM. There are no workarounds to mitigate the problem, but Cisco is providing fixes. This issue with Cisco vulnerabilities is the latest of several in the past month.

Tags: Secure Remote AccessDenial of Service (DoS) Attack PreventionVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Secure Remote Access
Endpoint protection best practices manual: Combating issues, problems
Best Mobile Data Security Products
Perimeter defense in the era of the perimeterless network
Securing the intranet with remote access VPN security
What security software should be installed on Internet café computers?
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?

Denial of Service (DoS) Attack Prevention
VeriSign extends DDoS attack protection service
Conficker authors prepping for next stage, researcher says
Latest DDoS attacks extremely unsophisticated, experts say
DDoS attacks hit U.S., South Korean government websites
How to prevent a denial-of-service (DoS) attack
I'll be watching you: Wireless IPS
How to prevent DDoS attacks on websites
How to prevent network denial-of-service attacks
What are 'phlashing' attacks?
Could someone place a rootkit on an internal network through a router?
Denial of Service (DoS) Attack Prevention Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts