Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc - | |
References | () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt - | |
References | () http://secunia.com/advisories/15393Â - | |
References | () http://secunia.com/advisories/15417/Â - Patch | |
References | () http://secunia.com/advisories/18222Â - | |
References | () http://secunia.com/advisories/18662Â - | |
References | () http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm - | |
References | () http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/637934Â - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/13676Â - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/20635Â - |
Information
Published : 2005-05-31 04:00
Updated : 2024-11-20 23:54
NVD link : CVE-2005-0356
Mitre link : CVE-2005-0356
CVE.ORG link : CVE-2005-0356
JSON object : View
Products Affected
nortel
- ethernet_routing_switch_1648
- universal_signaling_point
- ethernet_routing_switch_1612
- business_communications_manager
- succession_communication_server_1000
- optical_metro_5000
- ethernet_routing_switch_1624
- optical_metro_5100
- 7250_wlan_access_point
- optical_metro_5200
- survivable_remote_gateway
- contact_center
- callpilot
- 7220_wlan_access_point
cisco
- ciscoworks_windows_wug
- sn_5420_storage_router
- e-mail_manager
- ciscoworks_common_management_foundation
- content_services_switch_11500
- call_manager
- ciscoworks_1105_hosting_solution_engine
- interactive_voice_response
- content_services_switch_11000
- content_services_switch_11050
- ciscoworks_cd1
- conference_connection
- ciscoworks_lms
- secure_access_control_server
- emergency_responder
- aironet_ap350
- content_services_switch_11501
- agent_desktop
- sn_5420_storage_router_firmware
- content_services_switch_11503
- ciscoworks_windows
- mgx_8230
- webns
- ciscoworks_1105_wireless_lan_solution_engine
- personal_assistant
- ip_contact_center_enterprise
- web_collaboration_option
- ciscoworks_vpn_security_management_solution
- ciscoworks_common_services
- ciscoworks_access_control_list_manager
- unity_server
- content_services_switch_11150
- aironet_ap1200
- meetingplace
- content_services_switch_11506
- sn_5428_storage_router
- intelligent_contact_manager
- remote_monitoring_suite_option
- content_services_switch_11800
- mgx_8250
- support_tools
- ip_contact_center_express
openbsd
- openbsd
hitachi
- gr3000
- gr4000
- gs4000
- alaxala
freebsd
- freebsd
yamaha
- rtx1100
- rt57i
- rt250i
- rtx1000
- rtx2000
- rtx1500
- rt105
- rtv700
- rt300i
microsoft
- windows_2003_server
- windows_2000
- windows_xp
f5
- tmos
alaxala
- alaxala_networks
CWE