Multiple Firewall Vendor Packet Flood State Table Filling Vulnerability
BID:6023
Info
Multiple Firewall Vendor Packet Flood State Table Filling Vulnerability
| Bugtraq ID: | 6023 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2002 12:00AM |
| Updated: | Oct 21 2002 12:00AM |
| Credit: | Stephen Gill is credited with discovery. |
| Vulnerable: |
NetScreen ScreenOS 3.0.3 r1.1 NetScreen ScreenOS 3.0.1 r2 NetScreen ScreenOS 3.0.1 r1 NetScreen ScreenOS 2.10 r4 NetScreen ScreenOS 2.10 r3 NetScreen ScreenOS 2.7.1 r3 NetScreen ScreenOS 2.7.1 r2 NetScreen ScreenOS 2.7.1 r1 NetScreen ScreenOS 2.7.1 |
| Not Vulnerable: |
Alcatel-Lucent OmniAccess 250 0 Alcatel-Lucent OmniAccess 210 0 |
Solution / Fix
Multiple Firewall Vendor Packet Flood State Table Filling Vulnerability
Solution:
Alcatel products may be affected by these vulnerabilities. The vendor mentions that the OmniAccess 200 series is designed to protect against these types of attacks and may not be vulnerable. Users should contact the vendor for information about which products are affected and how to obtain any available fixes.
NetScreen has acknowledged that some of their product line is affected. Users should contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Alcatel products may be affected by these vulnerabilities. The vendor mentions that the OmniAccess 200 series is designed to protect against these types of attacks and may not be vulnerable. Users should contact the vendor for information about which products are affected and how to obtain any available fixes.
NetScreen has acknowledged that some of their product line is affected. Users should contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.