FreeBSD mbuf Flaw Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1009276 |
|
SecurityTracker URL: http://securitytracker.com/id/1009276
|
|
CVE Reference:
CAN-2004-0171
(Links to External Site)
|
Updated: Mar 2 2004
|
Original Entry Date: Mar 1 2004
|
Impact:
Denial of service via network
|
Vendor Confirmed: Yes
|
Version(s): 4.x, 5.x
|
Description:
A denial of service vulnerability was reported in the FreeBSD kernel. A remote user can cause the target system to run out of memory and stop processing new connections.
It is reported that a remote user can send TCP packets in the incorrect sequence to trigger a flaw in the FreeBSD kernel memory buffers. A low bandwidth attack can reportedly cause the target system to run out of memory. As a result, the target system will no longer process new connections as long as the affected TCP socket remains open.
iDEFENSE is credited with reporting this flaw.
The original message is available at:
http://docs.freebsd.org/cgi/getmsg.cgi?fetch=97407+0+/usr/local/www/db/text/2004/freebsd-net/20040222.freebsd-net
|
Impact:
A remote user can cause the target system to stop accepting connections.
|
Solution:
It is reported that a fix has been committed to the -current branch and that an advisory from the vendor is pending.
|
Vendor URL: www.freebsd.org/ (Links to External Site)
|
Cause:
Resource error, State error
|
Underlying OS:
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|