Tru64 Malformed TCP Packet Denial Of Service Vulnerability
BID:4011
Info
Tru64 Malformed TCP Packet Denial Of Service Vulnerability
| Bugtraq ID: | 4011 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jan 31 2002 12:00AM |
| Credit: | This vulnerability was independently discovered and reported by Luca Papotti <[email protected]> in July, 2001. Aditionally, this vulnerability was announced by Jason Johns - SAS(IT) <[email protected]> on January 30, 2002. |
| Vulnerable: |
Digital Ultrix 4.5 Digital Ultrix 4.4 Digital Ultrix 4.3 a Digital Ultrix 4.3 Digital Ultrix 4.2 Digital Ultrix 4.1 Digital Ultrix 4.0 Digital Ultrix 3.0 Digital Ultrix 2.2 Digital OSF/1 4.0 Digital OSF/1 3.2 G Digital OSF/1 3.2 F Digital OSF/1 3.2 DE2 Digital OSF/1 3.2 DE1 Digital OSF/1 3.2 D Digital OSF/1 3.2 C Digital OSF/1 3.2 B Digital OSF/1 3.2 Digital OSF/1 3.0 B Digital OSF/1 3.0 Digital OSF/1 2.1 B Digital OSF/1 2.1 Digital OSF/1 2.0 B Digital OSF/1 2.0 Digital OSF/1 1.3 A Digital OSF/1 1.3 Digital OSF/1 1.2 Compaq Tru64 4.0 e |
| Not Vulnerable: | |
Discussion
Tru64 Malformed TCP Packet Denial Of Service Vulnerability
It has been reported that Tru64 systems may be prone to a denial of service condition when handling malformed TCP packets.
Specifically, when processing a malformed TCP packet with both the SYN and FIN flags set, vulnerable Tru64 systems may block indefinitely, thus causing a denial of service. As a result other legitimate users may no longer be capable of accessing remote services.
This vulnerability is said to affect Tru64 4.0E as well as various versions of Digital Unix and VxWorks.
It has been reported that Tru64 systems may be prone to a denial of service condition when handling malformed TCP packets.
Specifically, when processing a malformed TCP packet with both the SYN and FIN flags set, vulnerable Tru64 systems may block indefinitely, thus causing a denial of service. As a result other legitimate users may no longer be capable of accessing remote services.
This vulnerability is said to affect Tru64 4.0E as well as various versions of Digital Unix and VxWorks.
Exploit / POC
Tru64 Malformed TCP Packet Denial Of Service Vulnerability
This vulnerability may be exploited with publicly available tools. The following proof of concept submitted by Luca Papotti has been made available using the hping2 utility:
hping2 -a <spoofed ip> -SPF -p 21 -c 1 <dest ip>
This vulnerability may be exploited with publicly available tools. The following proof of concept submitted by Luca Papotti has been made available using the hping2 utility:
hping2 -a <spoofed ip> -SPF -p 21 -c 1 <dest ip>
Solution / Fix
Tru64 Malformed TCP Packet Denial Of Service Vulnerability
Solution:
It has been reported that a patch has been released to address this issue, however this information has not been confirmed.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that a patch has been released to address this issue, however this information has not been confirmed.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tru64 Malformed TCP Packet Denial Of Service Vulnerability
References:
References: