FreeIPS Protected Service Denial Of Service Vulnerability
BID:10541
Info
FreeIPS Protected Service Denial Of Service Vulnerability
| Bugtraq ID: | 10541 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2004 12:00AM |
| Updated: | Jun 14 2004 12:00AM |
| Credit: | <[email protected]> reported this vulnerability to Bugtraq. |
| Vulnerable: |
FreeIPS FreeIPS 1.0 |
| Not Vulnerable: | |
Discussion
FreeIPS Protected Service Denial Of Service Vulnerability
It is reported that FreeIPS is susceptible to a denial of service vulnerability.
FreeIPS scans TCP connections for particular strings, defined by regular expressions. If a packet matches the regular expression, FreeIPS assumes malicious intent and attempts to close the TCP connection. It accomplishes this by sending TCP RST packets to both the client (attacker) and the server (victim TCP server).
The software correctly generates a TCP RST+ACK packet to the originating client, but the packet sent to the server is incorrectly generated. The packet sent to the server contains invalid sequence and acknowledgment numbers and is ignored.
An attacker can deny service to any TCP application protected by FreeIPS, denying network service to legitimate users.
The attacker would have to know or guess a string pattern that matches a regular expression in FreeIPS to successfully exploit this vulnerability.
It is reported that FreeIPS is susceptible to a denial of service vulnerability.
FreeIPS scans TCP connections for particular strings, defined by regular expressions. If a packet matches the regular expression, FreeIPS assumes malicious intent and attempts to close the TCP connection. It accomplishes this by sending TCP RST packets to both the client (attacker) and the server (victim TCP server).
The software correctly generates a TCP RST+ACK packet to the originating client, but the packet sent to the server is incorrectly generated. The packet sent to the server contains invalid sequence and acknowledgment numbers and is ignored.
An attacker can deny service to any TCP application protected by FreeIPS, denying network service to legitimate users.
The attacker would have to know or guess a string pattern that matches a regular expression in FreeIPS to successfully exploit this vulnerability.
Exploit / POC
FreeIPS Protected Service Denial Of Service Vulnerability
A proof of concept exploit was provided by <[email protected]>.
A proof of concept exploit was provided by <[email protected]>.
Solution / Fix
FreeIPS Protected Service Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.