Full Disclosure mailing list archives
Linux Kernel Fragment Reassembly DoS
From: "Gregory A. Gilliss" <ggilliss () netpublishing com>
Date: Sun, 22 Feb 2004 10:45:09 -0800
http://www.securityfocus.com/bid/7797 securityFocus is reporting that there exists a DoS associated with the handling of TCP packet reassembly in Linux (all versions vulnerable). Question - does that include broadcast addresses? If so, conceivably one could incapacitate all computers on a subnet with one fragment a la teardrop/Winnuke. G -- Gregory A. Gilliss, CISSP E-mail: greg () gilliss com Computer Security WWW: http://www.gilliss.com/greg/ PGP Key fingerprint 2F 0B 70 AE 5F 8E 71 7A 2D 86 52 BA B7 83 D9 B4 14 0E 8C A3 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Linux Kernel Fragment Reassembly DoS Gregory A. Gilliss (Feb 22)
