SunOS can be crashed with malformed UDP packets
| udp-bomb (143) |
Description:
By sending a UDP packet constructed with illegal values in certain fields, an attacker can crash some older Unix systems. Most operating systems that are not vulnerable to this attack will discard the invalid packet without retaining evidence indicating that an attack occurred.
Platforms Affected:
- Sun, SunOS 4.0.3
- Sun, SunOS 4.0.3c
- Sun, SunOS 4.1
- Sun, SunOS 4.1.1
- Sun, SunOS 4.1.2
- Sun, SunOS 4.1.3
- Sun, SunOS 4.1.3a1
- Sun, SunOS 4.1psr_a
Remedy:
Apply the Sun Patch ID#100567-04, available from the SunSolve Online: Patches Web site. See References.
Consequences:
Denial of Service
References:
- Sun Microsystems, Inc. Web site, SunSolve Online: Patches at http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access.
- CVE-1999-0217: Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.
Reported:
Jan 01, 1997
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
