The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252.
http://www.vupen.com/english/advisories/2009/2759
http://www.securityfocus.com/bid/36495
http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8119.shtml
http://tools.cisco.com/security/center/viewAlert.x?alertId=18876