[59756] in North American Network Operators' Group
Re: Patching for Cisco vulnerability
daemon@ATHENA.MIT.EDU (Petri Helenius)
Fri Jul 18 16:04:55 2003
From: "Petri Helenius" <pete@he.iki.fi>
To: "Jared Mauch" <jared@puck.Nether.net>, <nanog@merit.edu>
Date: Fri, 18 Jul 2003 23:03:59 +0300
Errors-To: owner-nanog-outgoing@merit.edu
>
> if (ifc->in_bps > ifc->phy_speed || ifc->out_bps > ifc->phy_speed)
> {
> crash_router();
> }
>
> If they added this code, they'd find these bugs in their
> labs instead of in our networks.
>
I remember seeing an article claiming that Cisco´s automated regression
testing does "more than 250000" tests before they release a piece of code.
However, questions about the nature of these tests and if any tests sent
more traffic than a random scripted ping went unanswered.
Pete