Datasheet

132
Release Notes for Cisco IOS Release 12.1E on the Catalyst 6500 and Cisco 7600 Supervisor Engine and MSFC
OL-2310-11
Caveats
Release 12.1(26)E and Rebuilds
General Caveats, page 132
FlexWAN Caveats, page 152
Service Module Caveats, page 155
OSM Caveats, page 157
Note The caveat lists for Release 12.1(26)E and rebuilds are updated frequently.
General Caveats
Open General Caveats in Release 12.1(26)E9, page 132
Resolved General Caveats in Release 12.1(26)E9, page 132
Resolved General Caveats in Release 12.1(26)E8, page 134
Resolved General Caveats in Release 12.1(26)E7, page 136
Resolved General Caveats in Release 12.1(26)E6, page 139
Resolved General Caveats in Release 12.1(26)E5, page 139
Resolved General Caveats in Release 12.1(26)E4, page 141
Resolved General Caveats in Release 12.1(26)E3, page 143
Resolved General Caveats in Release 12.1(26)E2, page 143
Resolved General Caveats in Release 12.1(26)E1, page 144
Resolved General Caveats in Release 12.1(26)E, page 145
Open General Caveats in Release 12.1(26)E9
None.
Resolved General Caveats in Release 12.1(26)E9
CSCin95836—Resolved in Release 12.1(26)E9.
The Cisco Next Hop Resolution Protocol (NHRP) feature in Cisco IOS contains a vulnerability that
can result in a restart of the device or possible remote code execution.
NHRP is a primary component of the Dynamic Multipoint Virtual Private Network (DMVPN)
feature.
NHRP can operate in three ways: at the link layer (Layer 2), over Generic Routing Encapsulation
(GRE) and multipoint GRE (mGRE) tunnels and directly on IP (IP protocol number 54). This
vulnerability affects all three methods of operation.
NHRP is not enabled by default for Cisco IOS.
This vulnerability is addressed by Cisco bug IDs CSCin95836 for non-12.2 mainline releases and
CSCsi23231 for 12.2 mainline releases.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20070808-nhrp.shtml.