imPC@ndo IT

Tracker / CVE-2008-4609

CVE-2008-4609

High 7.1

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.

Affected products and versions

bsd bsd
bsdi bsd_os
cisco catalyst_blade_switch_3020_firmware · … → 12.2\(50\)
cisco catalyst_blade_switch_3120_firmware · … → 12.2\(50\)
cisco catalyst_blade_switch_3120x_firmware · … → 12.2\(50\)
cisco ios
dragonflybsd dragonflybsd
freebsd freebsd
linux linux_kernel
microsoft windows_2000
microsoft windows_server_2003
microsoft windows_server_2008
microsoft windows_vista
microsoft windows_xp
midnightbsd midnightbsd
netbsd netbsd
openbsd openbsd
oracle solaris
trustedbsd trustedbsd

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References