The CERT Coordination Center has posted a long list (http://www.kb.cert.org/vuls/id/412115) of network vendors' products that could be vulnerable to the flaw. However, as of now, the majority of vendors haven't disclosed whether their device drivers are at risk. So far, Cisco Systems, F5 Networks, Hitachi, Microsoft, and NEC have reported that they're not vulnerable. According to @stake's advisory, the software and hardware vendors were notified of the potential flaw in June 2002. According to CERT, no statement concerning this vulnerability is yet available from more than 40 of the vendors notified more than six months ago.
According to the IEEE Ethernet standard, packets sent over the network should be at least 46 bytes in size. However, it's common for protocols, such as IP, to require packets of less than 46 bytes; in such cases, the remaining frames should contain null, or "empty," data.
Researchers from @stake say their tests reveal that instead of worthless packets stuffing the remaining bytes, potentially sensitive corporate information stored in memory buffers on the network interface card, static system memory controlled by the network driver, or kernel memory is sent instead. "The number of affected systems is staggering, and the number of vulnerable systems used as critical network infrastructure terrifying. The security of proprietary network devices is particularly questionable," @stake wrote in the conclusion of its paper.
Both CERT and @stake recommend vulnerable companies encrypt network traffic, but even encrypting all network traffic isn't foolproof protection. While at-risk networks will greatly reduce this vulnerability's impact through encryption, they warn, sensitive information leaked from such sources as kernel memory can still be viewed by prying eyes.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.