INFORMATION
Name | : | CVE-2008-4609 | First Publication | : | 2008-10-20 |
Severity | : | High | Last Modification | : | 2009-06-30 |
SCORING CVSS v2
Cvss Base Score | : | 7.1 | Attack Range | : | Network |
Cvss Impact Score | : | 6.9 | Attack Complexity | : | Medium |
Cvss Expoit Score | : | 8.6 | Authentification | : | None Required |
Calculate full CVSS 2.0 Vectors scores | |||||
DETAIL
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.Please see also:
http://blog.robertlee.name/2008/10/more-detailed-response-to-gordons-post.html
and
http://www.curbrisk.com/security-blog/robert-e-lee-discusses-tcp-denial-service-vulnerability-sc-magazine.html




(High)



