SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Networking Stack (TCP/IP)  >   TCP/IP Stack Implementation Vendors:   Compaq
Compaq Tru64 Networking Stack Allows Remote Users to Cause Connections to Freeze
SecurityTracker Alert ID:  1003408
SecurityTracker URL:  http://securitytracker.com/id/1003408
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Updated:  Jan 31 2002
Original Entry Date:  Jan 31 2002
Impact:   Denial of service via network
Exploit Included:  Yes  

Description:   A denial of service vulnerability was reported in Compaq's Tru64 operating system's networking stack. A remote user can cause connections to freeze and/or be blocked.

It is reported that a remote user can conduct a network scan (using nmap, for example) against a Compaq Tru64 host to cause the telnet and ftp connections to freeze and timeout. It is reported that new connections will be denied for a temporary period of time (~ 1 minute).

The following nmap command line was used to trigger this flaw:

nmap -T Polite -O -p 23,139 -oM /tmp/lst 'xxx.xxx.16-44.*'

Impact:   A remote user can cause the operating system's networking stack to freeze connections and refuse new connections for a period of time.
Solution:   No solution was available at the time of this entry.
Vendor URL:  www.tru64unix.compaq.com/ (Links to External Site)
Cause:   Exception handling error
Underlying OS:   UNIX (Tru64)

Message History:   None.


 Source Message Contents

Date:  Wed, 30 Jan 2002 10:27:21 -0600
Subject:  DoS bug on Tru64


Today we were using nmap to scan our network and when we scanned our
Tru64 machines, telnet and ftp froze and timed out. We could not make
any connections to those ports and existing connections froze. New
connections were denied for about a minute after the scan was finished.
I've checked with Compaq and on Securityfocus and neither place has any
knowledge of this. 

We are running Tru64 Unix 4.0D patch kit 3 on Alpha 4100's and 8400's.
The nmap command line that was used is:
nmap -T Polite -O -p 23,139 -oM /tmp/lst 'xxx.xxx.16-44.*' 


/Jason Johns


 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC