CVE-2009-1154
https://notcve.org/view.php?id=CVE-2009-1154
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute. Cisco IOS XR 3.8.1 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (caida de proceso) mediante un mensaje BGP UPDATE, como se ha demostrado con un mensaje con muchos números AS en el AS Path Attribute. • http://securitytracker.com/id?1022756 http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-2055 – Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2009-2055
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. Cisco IOS XR desde la v3.4.0 hasta la v3.8.1 permite a atacantes remotos producir una denegación de servicio (reset de sesión) a través de el mensaje BGP UPDATE con un atributo invalido, como se demostró el 17 de Agosto de 2009. Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). • http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html http://securitytracker.com/id?1022739 http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml • CWE-20: Improper Input Validation •