
689
Caveats for Cisco IOS Release 12.2(33)SRD through 12.2(33)SRD8
OL-10394-05 Rev. R0
Cisco 10000, uBR10012 and uBR7200 series devices use a User Datagram Protocol (UDP) based
Inter-Process Communication (IPC) channel that is externally reachable. An attacker could exploit
this vulnerability to cause a denial of service (DoS) condition on affected devices. No other
platforms are affected.
Cisco has released free software updates that address this vulnerability. Workarounds that mitigate
this vulnerability are available.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080924-ipc.shtml
• CSCsh33518
Symptoms: When STP is configured on a Cisco Catalyst 6500 switch with Active and Standby SUP
the show spanning tree command on the Standby SUP may show different information from that
of Active SUP.
For example:
Active SUP xs6k3#sh spanning-tree
VLAN0002 Spanning tree enabled protocol ieee Root ID Priority 32768 Address
0014.1bc4.c002 Cost 4 Port 259 (GigabitEthernet3/3) Hello Time 2 sec Max Age 20 sec
Forward Delay 15 sec
Bridge ID Priority 32768 Address 0014.1bc4.f802 Hello Time 2 sec Max Age 20 sec
Forward Delay 15 sec Aging Time 15
Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- --------
---------------------------- - --- Gi3/3 Root FWD 4 128.259 P2p Gi3/4 Altn BLK 4
128.260 P2p
xs6k3#
Spanning Tree info on Standby ------------------------------ xs6k3-sdby#sh
spanning-tree
No spanning tree instance exists.
xs6k3-sdby#
Conditions: This condition is generic for Cisco IOS Release 12.2(18)SXF6 and earlier releases.
Trigger: This problem is due to the different load conditions on the Active and Standby SUP.
Impact: No spanning tree instance exists on standby.
Workaround: Manually reset Standby SUP to re-sync STP states from Active to Standby. However
the STP states may digress again going forward.
Further Problem Description: This problem is due to the different load conditions on the Active and
Standby SUP. Occasionally the Standby SUP may run ahead of Active SUP in terms of sync state.
When there is a surge of activities on the Active SUP it may run behind the sync request/event
coming from the Standby. When the sync event arrives too early the Active SUP drops the request
due to wrong state/event combination and therefore the sync never happened and hence the
discrepancy.
A fix is put in place to avoid this type of sync race condition between Active and Standby.
• CSCsh47251
Symptoms: A Cisco 3700 or 3800 series router crashes on bootup.
Conditions: The crash happens only when two conditions are satisfied:
1) An NM-xDM card is present in the box. 2) An external compact flash is present (inserted) in the
box.
Workaround: Remove the external compact flash before booting the router.
• CSCsh48919
Symptoms: With an ATA flash card, the dir disk0: command will fail if any filename or directory
name stored on disk0 contains embedded spaces. This applies to disk1 or disk2 as well. This
situation can also occur with a compact flash (CF) card using the dir flash: command.
Comentarios a estos manuales