Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8005 | vendor advisory |
http://www.securityfocus.com/bid/71287 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=36532 | vendor advisory |
http://www.securitytracker.com/id/1031262 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98937 | vdb entry |