Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc - | |
References | () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt - | |
References | () http://secunia.com/advisories/15393Â - | |
References | () http://secunia.com/advisories/15417/Â - Patch | |
References | () http://secunia.com/advisories/18222Â - | |
References | () http://secunia.com/advisories/18662Â - | |
References | () http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm - | |
References | () http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/637934Â - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/13676Â - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/20635Â - |
Information
Published : 2005-05-31 04:00
Updated : 2024-11-20 23:54
NVD link : CVE-2005-0356
Mitre link : CVE-2005-0356
CVE.ORG link : CVE-2005-0356
JSON object : View
Products Affected
yamaha
- rt105
- rtx1500
- rtx1000
- rtx2000
- rt300i
- rtx1100
- rt57i
- rtv700
- rt250i
cisco
- ciscoworks_vpn_security_management_solution
- remote_monitoring_suite_option
- content_services_switch_11500
- content_services_switch_11000
- ciscoworks_common_management_foundation
- content_services_switch_11150
- sn_5420_storage_router_firmware
- aironet_ap1200
- sn_5420_storage_router
- web_collaboration_option
- support_tools
- aironet_ap350
- content_services_switch_11503
- secure_access_control_server
- mgx_8230
- ciscoworks_common_services
- agent_desktop
- content_services_switch_11501
- sn_5428_storage_router
- interactive_voice_response
- conference_connection
- mgx_8250
- e-mail_manager
- content_services_switch_11050
- ciscoworks_access_control_list_manager
- call_manager
- ip_contact_center_enterprise
- ip_contact_center_express
- ciscoworks_cd1
- emergency_responder
- personal_assistant
- content_services_switch_11800
- content_services_switch_11506
- intelligent_contact_manager
- webns
- ciscoworks_1105_wireless_lan_solution_engine
- ciscoworks_windows
- ciscoworks_windows_wug
- unity_server
- ciscoworks_lms
- meetingplace
- ciscoworks_1105_hosting_solution_engine
nortel
- 7250_wlan_access_point
- survivable_remote_gateway
- optical_metro_5000
- 7220_wlan_access_point
- optical_metro_5100
- contact_center
- optical_metro_5200
- ethernet_routing_switch_1612
- ethernet_routing_switch_1648
- callpilot
- universal_signaling_point
- succession_communication_server_1000
- ethernet_routing_switch_1624
- business_communications_manager
hitachi
- gr4000
- alaxala
- gr3000
- gs4000
openbsd
- openbsd
microsoft
- windows_xp
- windows_2003_server
- windows_2000
f5
- tmos
freebsd
- freebsd
alaxala
- alaxala_networks
CWE