imPC@ndo IT

Tracker / CVE-2001-1244

CVE-2001-1244

Medium 5.0

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

Affected products and versions

freebsd freebsd
hp hp-ux
hp vvos
linux linux_kernel
microsoft windows_2000
microsoft windows_nt
netbsd netbsd
openbsd openbsd
sun sunos

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References