Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
BID:11258
Info
Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
| Bugtraq ID: | 11258 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-4316 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2004 12:00AM |
| Updated: | May 30 2007 06:01PM |
| Credit: | Discovery of this vulnerability is credited to Gandalf The White <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Linux kernel 2.4.27 -pre5 Linux kernel 2.4.27 -pre4 Linux kernel 2.4.27 -pre3 Linux kernel 2.4.27 -pre2 Linux kernel 2.4.27 -pre1 Linux kernel 2.4.26 Linux kernel 2.4.25 Linux kernel 2.4.24 -ow1 Linux kernel 2.4.24 Linux kernel 2.4.23 -pre9 Linux kernel 2.4.23 -ow2 Linux kernel 2.4.23 Linux kernel 2.4.22 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.19 Linux kernel 2.4.18 pre-8 Linux kernel 2.4.18 pre-7 Linux kernel 2.4.18 pre-6 Linux kernel 2.4.18 pre-5 Linux kernel 2.4.18 pre-4 Linux kernel 2.4.18 pre-3 Linux kernel 2.4.18 pre-2 Linux kernel 2.4.18 pre-1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 .0-test9 Linux kernel 2.4 .0-test8 Linux kernel 2.4 .0-test7 Linux kernel 2.4 .0-test6 Linux kernel 2.4 .0-test5 Linux kernel 2.4 .0-test4 Linux kernel 2.4 .0-test3 Linux kernel 2.4 .0-test2 Linux kernel 2.4 .0-test12 Linux kernel 2.4 .0-test11 Linux kernel 2.4 .0-test10 Linux kernel 2.4 .0-test1 Linux kernel 2.4 IBM AIX 5.3 L IBM AIX 5.2 L IBM AIX 5.1 L IBM AIX 5.3 IBM AIX 5.2 IBM AIX 5.1 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.04 HP HP-UX B.11.00 Avaya Predictive Dialing System (PDS) 12.0 Avaya Predictive Dialing System (PDS) 11.0 Avaya Predictive Dialing System (PDS) 9.0 Avaya Predictive Dialer 0 |
| Not Vulnerable: |
Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X 10.3.5 |
Discussion
Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
Multiple vendor implementations of the TCP stack are reported prone to a remote denial-of-service vulnerability.
The issue is reported to present itself due to inefficiencies present when handling fragmented TCP packets.
The discoverer of this issue has dubbed the attack style the "New Dawn attack"; it is a variation of a previously reported attack that was named the "Rose Attack".
A remote attacker may exploit this vulnerability to deny service to an affected computer.
Microsoft Windows 2000/XP, Linux kernel 2.4 tree, and undisclosed Cisco systems are reported prone to this vulnerability; other products may also be affected.
Multiple vendor implementations of the TCP stack are reported prone to a remote denial-of-service vulnerability.
The issue is reported to present itself due to inefficiencies present when handling fragmented TCP packets.
The discoverer of this issue has dubbed the attack style the "New Dawn attack"; it is a variation of a previously reported attack that was named the "Rose Attack".
A remote attacker may exploit this vulnerability to deny service to an affected computer.
Microsoft Windows 2000/XP, Linux kernel 2.4 tree, and undisclosed Cisco systems are reported prone to this vulnerability; other products may also be affected.
Exploit / POC
Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
Solution:
Please see the referenced vendor advisories for information on obtaining fixes.
HP HP-UX B.11.04
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
HP HP-UX B.11.23
HP HP-UX B.11.00
Solution:
Please see the referenced vendor advisories for information on obtaining fixes.
HP HP-UX B.11.04
-
HP PHNE_33427
http://itrc.hp.com
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
HP HP-UX B.11.23
-
HP PHKL_31500
http://itrc.hp.com
HP HP-UX B.11.00
-
HP PHNE_30161
http://itrc.hp.com
References
Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
References:
References:
- ASA-2006-062 - HP-UX running TCP/IP Remote Denial of Service (DoS) (HPSBUX02087) (Avaya)
- HPSBUX02087 SSRT4728 - HP-UX running TCP/IP Remote Denial of Service (DoS) (HP)
- HPSBUX02087 SSRT4728 rev.1 - HP-UX running TCP/IP Remote Denial of Service (DoS) (HP)
- IPv4 fragmentation --> The Rose Attack (Gandalf The White
) - Avaya Security Advisory ASA-2006-228 (Avaya)