PT-2014-2920 · Ibm · Ibm Networking Operating System+3
Published
2014-01-02
·
Updated
2014-01-28
·
CVE-2013-5385
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
IBM i versions 6.1 through 7.1
z/OS on zSeries servers (affected versions not specified)
Networking Operating System (NOS) (affected versions not specified)
Description
The issue concerns the OSPF implementation, which fails to properly validate Link State Advertisement (LSA) type 1 packets. This allows remote attackers to cause a denial of service, resulting in routing disruption, or obtain sensitive packet information by sending a crafted LSA packet.
Recommendations
For IBM i versions 6.1 through 7.1, update the OSPF implementation to properly validate LSA type 1 packets.
For z/OS on zSeries servers, apply the necessary configuration changes to the OSPF implementation to prevent the issue.
For Networking Operating System (NOS), restrict access to the LSA database until a proper validation mechanism is implemented.
As a temporary workaround, consider disabling the OSPF implementation until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm I
Ibm Networking Operating System
Z/Os
Zseries