OSVDB ID: 4030

Title: TCP/IP Sequence Prediction Blind Reset Spoofing DoS

Info

Disclosure

Apr 20, 2004

Discovery

Jul 30, 2003

Dates

Exploit

Unknown

Solution

Unknown

Description

The TCP stack implementation of numerous vendors contains a flaw that may allow a remote denial of service. The issue is triggered when spoofed TCP Reset packets are received by the targeted TCP stack, and will result in loss of availability for the attacked TCP services.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Denial of Service, Hijacking, Infrastructure
Impact: Loss of Availability
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Install vendor upgrades or patches to resolve this issue. Routers using BGP are highly recommended to implement RFC-2385 (BGP TCP MD5 Signatures) as a work-around.

Products

Check Point Software Technologies, Inc.

FireWall-1

Prior to R55 HFA-03

Cisco Systems, Inc.

IOS

All Versions

Cray, Inc.

Unicos

All Versions

Hewlett-Packard Development Company, L.P.

HP-UX

All Versions

Internet Security Systems

Proventia M Series

1.5

Juniper Networks, Inc.

Router

All Versions

Linux

Linux

All Versions

Microsoft Corporation

Windows

All Versions

Nokia

IPSO

All Versions

References

Credit

  • Paul (Tony) Watson - pawBrand New Doo Doopaw.org - OSVDB


Direct URL: http://osvdb.org/36218