Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
BID:16595
Info
Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
| Bugtraq ID: | 16595 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2006 12:00AM |
| Updated: | Feb 13 2006 06:28PM |
| Credit: | Discovered by Jon Oberheide. |
| Vulnerable: |
Honeyd Honeyd 0.8 Honeyd Honeyd 0.7 a Honeyd Honeyd 0.7 Honeyd Honeyd 0.6 a Honeyd Honeyd 0.6 Honeyd Honeyd 0.5 Honeyd Honeyd 1.0 Honeyd Honeyd 0.8b Honeyd Honeyd 0.8a |
| Not Vulnerable: |
Honeyd Honeyd 1.5 |
Discussion
Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
Honeyd is prone to a virtual host-detection vulnerability.
The vulnerability presents itself in the IP reassembly code.
A successful attack may allow remote attackers to enumerate the existence of simulated Honeyd hosts and then either target specific attacks against these hosts or avoid them altogether.
This issue affects all versions of Honeyd prior to 1.5.
Honeyd is prone to a virtual host-detection vulnerability.
The vulnerability presents itself in the IP reassembly code.
A successful attack may allow remote attackers to enumerate the existence of simulated Honeyd hosts and then either target specific attacks against these hosts or avoid them altogether.
This issue affects all versions of Honeyd prior to 1.5.
Exploit / POC
Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
Solution:
The vendor has released Honeyd 1.5 to address this issue.
A patch is available from the following location as well:
http://www.honeyd.org/adv.2006-01.patchhttp://www.honeyd.org/adv.2006-01.patch
Solution:
The vendor has released Honeyd 1.5 to address this issue.
A patch is available from the following location as well:
http://www.honeyd.org/adv.2006-01.patchhttp://www.honeyd.org/adv.2006-01.patch
References
Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
References:
References:
- Honeyd bug fixes (Niels Provos
) - Honeyd Homepage (Honeyd)