SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   OS (UNIX)  >   FreeBSD Kernel Vendors:   FreeBSD
FreeBSD mbuf Flaw Lets Remote Users Deny Service
SecurityTracker Alert ID:  1009276
SecurityTracker URL:  http://securitytracker.com/id/1009276
CVE Reference:   CAN-2004-0171   (Links to External Site)
Updated:  Mar 2 2004
Original Entry Date:  Mar 1 2004
Impact:   Denial of service via network
Vendor Confirmed:  Yes  
Version(s): 4.x, 5.x
Description:   A denial of service vulnerability was reported in the FreeBSD kernel. A remote user can cause the target system to run out of memory and stop processing new connections.

It is reported that a remote user can send TCP packets in the incorrect sequence to trigger a flaw in the FreeBSD kernel memory buffers. A low bandwidth attack can reportedly cause the target system to run out of memory. As a result, the target system will no longer process new connections as long as the affected TCP socket remains open.

iDEFENSE is credited with reporting this flaw.

The original message is available at:

http://docs.freebsd.org/cgi/getmsg.cgi?fetch=97407+0+/usr/local/www/db/text/2004/freebsd-net/20040222.freebsd-net

Impact:   A remote user can cause the target system to stop accepting connections.
Solution:   It is reported that a fix has been committed to the -current branch and that an advisory from the vendor is pending.
Vendor URL:  www.freebsd.org/ (Links to External Site)
Cause:   Resource error, State error
Underlying OS:  

Message History:   This archive entry has one or more follow-up message(s) listed below.
Mar 2 2004 (Advisory is Available) FreeBSD mbuf Flaw Lets Remote Users Deny Service   (idlabs-advisories@idefense.com)
iDEFENSE has released their official advisory.
Mar 2 2004 (FreeBSD Issues Fix) FreeBSD mbuf Flaw Lets Remote Users Deny Service   (FreeBSD Security Advisories <security-advisories@freebsd.org>)
FreeBSD has released a fix.
Sep 29 2004 (SGI Issues Fix for IRIX) FreeBSD mbuf Flaw Lets Remote Users Deny Service   (SGI Security Coordinator <agent99@sgi.com>)
SGI has released a fix for SGI IRIX.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC