|
Windows Packet Fragmentation Handling Denial of Service Vulnerability
|
|
Secunia Advisory:
|
SA12670
|
|
|
Release Date:
|
2004-10-01
|
|
Popularity:
|
14,669 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| OS: | Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Gandalf The White has reported a variant of some known vulnerabilities in Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error within the processing of fragmented packets. This can be exploited by sending a large number of small fragmented packets where some fragments are missing and then sending the final fragment repeatedly.
Successful exploitation may consume a large amount of CPU resources on a vulnerable system and may cause legitimate fragmented packets to be dropped, if a sufficient amount of attacking systems is used.
Solution: Secunia is currently not aware of a solution.
Provided and/or discovered by: Gandalf The White
Other References: http://digital.net/~gandalf/Rose_Frag_Attack_Explained.txt
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|