NFR Null TCP Packet Vulnerability
BID:63
Info
NFR Null TCP Packet Vulnerability
| Bugtraq ID: | 63 |
| Class: | Unknown |
| CVE: |
CVE-1999-1503 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was published as "interesting ..." by Mudge <[email protected]> on the nfr-users mailing list. |
| Vulnerable: |
NFR NFR 1.6.1 NFR NFR 1.5 |
| Not Vulnerable: | |
Discussion
NFR Null TCP Packet Vulnerability
Upon receiving a IP packet with the protocol field set to TCP but with an all null TCP header and data section nfrd will die.
nfrd wiill be automatically restarted but the attack packet does not get logged. The nfrd.log file will also be overwritten by the new instance of nfrd.
This opens a window of opourtunity for an attacker to send packets that will not be process by nfrd while it is restarting.
Upon receiving a IP packet with the protocol field set to TCP but with an all null TCP header and data section nfrd will die.
nfrd wiill be automatically restarted but the attack packet does not get logged. The nfrd.log file will also be overwritten by the new instance of nfrd.
This opens a window of opourtunity for an attacker to send packets that will not be process by nfrd while it is restarting.
Exploit / POC
NFR Null TCP Packet Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].