Compaq TruCluster Port Scan Denial of Service Vulnerability
BID:3362
Info
Compaq TruCluster Port Scan Denial of Service Vulnerability
| Bugtraq ID: | 3362 |
| Class: | Unknown |
| CVE: |
CVE-2001-1033 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced to Bugtraq by Andrew Leonard <[email protected]> on September 25, 2001. |
| Vulnerable: |
Compaq TruCluster 1.5 |
| Not Vulnerable: | |
Discussion
Compaq TruCluster Port Scan Denial of Service Vulnerability
TruCluster is a server high-availability software package distributed and maintained by Compaq.
A problem has been discovered that could allow a denial of service to users of the TruCluster package. The problem is in the handling of portscans by the software. When a system in a cluster is portscanned by a system without a DNS PTR record, cluster split-brain occurs.
This makes it possible for a user to corrupt or destroy data, deny service, and perhaps even damage hardware.
TruCluster is a server high-availability software package distributed and maintained by Compaq.
A problem has been discovered that could allow a denial of service to users of the TruCluster package. The problem is in the handling of portscans by the software. When a system in a cluster is portscanned by a system without a DNS PTR record, cluster split-brain occurs.
This makes it possible for a user to corrupt or destroy data, deny service, and perhaps even damage hardware.
Exploit / POC
Compaq TruCluster Port Scan Denial of Service Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Compaq TruCluster Port Scan Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Compaq TruCluster Port Scan Denial of Service Vulnerability
References:
References: