CVE-2004-0230
⚪ Do wiadomości
Wykorzystanie dużego rozmiaru okna TCP umożliwia atakującym zdalne zrywanie połączeń.
CVSS
5.0
EPSS
80.3%
Exploit
poc
Vendor
juniper
Opis źródłowy (NVD)
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 80.3% |
| Opublikowano (NVD) | 2004-08-18 04:00:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 20:17:02 UTC |
Referencje
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc ([email protected]) [Broken Link, Third Party Advisory]
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt ([email protected]) [Broken Link, Third Party Advisory]
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt ([email protected]) [Broken Link, Third Party Advisory]
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt ([email protected]) [Broken Link, Third Party Advisory]
- ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc ([email protected]) [Broken Link, Third Party Advisory]
- http://kb.juniper.net/JSA10638 ([email protected]) [Third Party Advisory]
- http://marc.info/?l=bugtraq&m=108302060014745&w=2 ([email protected]) [Mailing List]
- http://marc.info/?l=bugtraq&m=108506952116653&w=2 ([email protected]) [Mailing List]
- http://secunia.com/advisories/11440 ([email protected]) [Broken Link, Permissions Required, Third Party Advisory, VDB Entry]
- http://secunia.com/advisories/11458 ([email protected]) [Broken Link, Permissions Required, Third Party Advisory, VDB Entry]
- http://secunia.com/advisories/22341 ([email protected]) [Broken Link, Permissions Required, Third Party Advisory, VDB Entry]
- http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml ([email protected]) [Broken Link]
- http://www.kb.cert.org/vuls/id/415294 ([email protected]) [Third Party Advisory, US Government Resource]
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html ([email protected]) [Patch, Third Party Advisory]
- http://www.osvdb.org/4030 ([email protected]) [Broken Link]
- http://www.securityfocus.com/archive/1/449179/100/0/threaded ([email protected]) [Broken Link]
- http://www.securityfocus.com/bid/10183 ([email protected]) [Exploit, Third Party Advisory, VDB Entry]
- http://www.uniras.gov.uk/vuls/2004/236929/index.htm ([email protected]) [Broken Link]
- http://www.us-cert.gov/cas/techalerts/TA04-111A.html ([email protected]) [Third Party Advisory, US Government Resource]
- http://www.vupen.com/english/advisories/2006/3983 ([email protected]) [Broken Link, Permissions Required]
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019 ([email protected]) [Third Party Advisory]
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-064 ([email protected]) [Third Party Advisory]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15886 ([email protected]) [Third Party Advisory]
- https://kc.mcafee.com/corporate/index?page=content&id=SB10053 ([email protected]) [Broken Link, Patch, Third Party Advisory]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2689 ([email protected]) [Broken Link]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A270 ([email protected]) [Broken Link]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3508 ([email protected]) [Broken Link]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4791 ([email protected]) [Broken Link]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5711 ([email protected]) [Broken Link]