CVE-2013-5385
02.01.2014, 14:59
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | i | 6.1 |
ibm | i | 7.1 |
ibm | z\/os | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References