Cisco Gigabit Ethernet Switch Module for HP BladeSystem p-Class Release Notes, Cisco IOS Release 12.2(25)SEE1 and later

19
Cisco Gigabit Ethernet Switch Module for HP BladeSystem p-Class Release Notes, Cisco IOS Release 12.2(25)SEE1 and later
459516-002
Resolved Caveats
CSCei80087
It is no longer necessary to detach and then reapply a hierarchical policy map to force changes to a
VLAN level class-map to take effect.
CSCek26492
Symptoms: A router may crash if it receives a packet with a specific crafted IP option as detailed in
Cisco Security Advisory: Crafted IP Option Vulnerability:
http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml
Conditions: This DDTS resolves a symptom of CSCec71950. Cisco IOS with this specific DDTS
are not at risk of crash if CSCec71950 has been resolved in the software.
Workaround: Cisco IOS versions with the fix for CSCec71950 are not at risk for this issue and no
workaround is required. If CSCec71950 is not resolved, see the following Cisco Security Advisory:
Crafted IP Option Vulnerability for workaround information:
http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-ip-option.shtml
CSCek37177
The Cisco IOS Transmission Control Protocol (TCP) listener in certain versions of Cisco IOS
software is vulnerable to a remotely-exploitable memory leak that may lead to a denial of service
condition.
This vulnerability only applies to traffic destined to the Cisco IOS device. Traffic transiting the
Cisco IOS device will not trigger this vulnerability.
Cisco has made free software available to address this vulnerability for affected customers.
This issue is documented as Cisco bug ID CSCek37177.
There are workarounds available to mitigate the effects of the vulnerability.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-tcp.shtml
CSCsb79198
A switch no longer fails IEEE 802.1x authentication if it downloads an access control list (ACL)
that has more than 20 ACL access control entries (ACEs) from a RADIUS server.
CSCsb82422
The switch now forwards an IEEE 802.1x request that has null credentials.
CSCsc13467
A switch no longer fails or displays illegal memory access messages during the SNMP Timer
process.
CSCsc58665
The ENTITY-MIB: entPhysicalVendorType now returns correct information for SFP ports.
CSCsc81978
When the switch displays a STORM_CONTROL-3-SHUTDOWN message and a port status changes to
disabled, the cpscEvent (cpscStatus) Trap now correctly shows that the
CPortStormControlStatusType is 5, which means shutdown.
In previous releases, the trap showed 2, which means forwarding.
CSCsc84627
A MAC entry no longer changes from static to dynamic on a switch configured with Private VLANs.