The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
|
History
21 Nov 2024, 00:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://blog.robertlee.name/2008/10/conjecture-speculation.html - Broken Link | |
References | () http://insecure.org/stf/tcp-dos-attack-explained.html - Broken Link | |
References | () http://lists.immunitysec.com/pipermail/dailydave/2008-October/005360.html - Broken Link | |
References | () http://marc.info/?l=bugtraq&m=125856010926699&w=2Â - Third Party Advisory | |
References | () http://searchsecurity.techtarget.com.au/articles/27154-TCP-is-fundamentally-borked - Broken Link | |
References | () http://www.cisco.com/en/US/products/products_security_advisory09186a0080af511d.shtml - Broken Link | |
References | () http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html - Broken Link | |
References | () http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf - Broken Link | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Â - Broken Link | |
References | () http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html - Third Party Advisory | |
References | () http://www.outpost24.com/news/news-2008-10-02.html - Broken Link | |
References | () http://www.us-cert.gov/cas/techalerts/TA09-251A.html - Third Party Advisory, US Government Resource | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-048Â - Patch, Third Party Advisory | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6340Â - Broken Link | |
References | () https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html - Broken Link |
Information
Published : 2008-10-20 17:59
Updated : 2025-04-09 00:30
NVD link : CVE-2008-4609
Mitre link : CVE-2008-4609
CVE.ORG link : CVE-2008-4609
JSON object : View
Products Affected
oracle
- solaris
bsd
- bsd
cisco
- catalyst_blade_switch_3120_firmware
- ios
- catalyst_blade_switch_3020
- catalyst_blade_switch_3120x
- catalyst_blade_switch_3120
- catalyst_blade_switch_3020_firmware
- catalyst_blade_switch_3120x_firmware
dragonflybsd
- dragonflybsd
netbsd
- netbsd
freebsd
- freebsd
microsoft
- windows_server_2003
- windows_xp
- windows_server_2008
- windows_2000
- windows_vista
openbsd
- openbsd
bsdi
- bsd_os
midnightbsd
- midnightbsd
trustedbsd
- trustedbsd
linux
- linux_kernel
CWE