CVE-2008-4609
published 2008-10-20CVE-2008-4609: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows…
high7.1CVSS 3.1
AVNACMAuNCNINAC
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
Affected
2023 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bsd | bsd | — | — |
| bsd | bsd | — | — |
| bsd | bsd | — | — |
| bsd | bsd | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| cisco | catalyst_blade_switch_3020_firmware | < 12.2\(50\) | 12.2\(50\) |
| cisco | catalyst_blade_switch_3120_firmware | < 12.2\(50\) | 12.2\(50\) |
| cisco | catalyst_blade_switch_3120x_firmware | < 12.2\(50\) | 12.2\(50\) |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvd7.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.1HIGH
GHSA
GHSA-vf4j-pjcc-qf79: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems
ghsa_unreviewed·2022-05-13
CVE-2008-4609 [HIGH] GHSA-vf4j-pjcc-qf79: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
GHSA
GHSA-jwpp-857g-6hpg: Unspecified vulnerability in Cisco NX-OS before 4
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2009-0627 [HIGH] GHSA-jwpp-857g-6hpg: Unspecified vulnerability in Cisco NX-OS before 4
Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.
OSV
CVE-2008-4609: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems
osv·2008-10-20·CVSS 7.1
CVE-2008-4609 [HIGH] CVE-2008-4609: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
Red Hat
kernel: TCP protocol vulnerabilities from Outpost24
vendor_redhat·2009-09-08·CVSS 7.1
CVE-2008-4609 [HIGH] kernel: TCP protocol vulnerabilities from Outpost24
kernel: TCP protocol vulnerabilities from Outpost24
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
Statement: The attacks reported by Outpost24 AB target the design limitations of the TCP protocol. Due to upstreams decision not to release updates, Red Hat do not plan to release updates to resolve these issues however, the effects of these attacks can be reduced via the mitigation methods as written in https://access.redhat.com/solutions/18729.
Cisco
TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
vendor_cisco·2009-09-08·CVSS 7.8
CVE-2008-4609 [HIGH] CWE-399 TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
Multiple Cisco products are affected by denial of service (DoS)
vulnerabilities that manipulate the state of Transmission Control Protocol
(TCP) connections. By manipulating the state of a TCP connection, an attacker
could force the TCP connection to remain in a long-lived state, possibly
indefinitely. If enough TCP connections are forced into a long-lived or
indefinite state, resources on a system under attack may be consumed,
preventing new TCP connections from being accepted. In some cases, a system
reboot may be necessary to recover normal system operation. To exploit these
vulnerabilities, an attacker must be able to complete a TCP three-way handshake
with a vulnerable system.
In addition to these vul
Debian
CVE-2008-4609: linux - The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Micros...
vendor_debian·2008·CVSS 7.1
CVE-2008-4609 [HIGH] CVE-2008-4609: linux - The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Micros...
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Cisco
TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
vendor_cisco
CVE-2008-4609 TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
CVE-2008-4609: TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products
Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of a TCP connection, an attacker could force the TCP connection to remain in a long-lived state, possibly indefinitely. If enough TCP connections are forced into a long-lived or indefinite state, resources on a system under attack may be consumed, preventing new TCP connections from being accepted. In some cases, a system reboot may be necessary to recover normal system operation. To exploit these vulnerabilities, an attacker must be able to complete a TCP three-way handshake with a vulnerable system. In additio
No detection rules found.
No public exploits indexed.
http://blog.robertlee.name/2008/10/conjecture-speculation.htmlhttp://insecure.org/stf/tcp-dos-attack-explained.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2008-October/005360.htmlhttp://marc.info/?l=bugtraq&m=125856010926699&w=2http://searchsecurity.techtarget.com.au/articles/27154-TCP-is-fundamentally-borkedhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080af511d.shtmlhttp://www.cisco.com/en/US/products/products_security_response09186a0080a15120.htmlhttp://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.outpost24.com/news/news-2008-10-02.htmlhttp://www.us-cert.gov/cas/techalerts/TA09-251A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6340https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.htmlhttp://blog.robertlee.name/2008/10/conjecture-speculation.htmlhttp://insecure.org/stf/tcp-dos-attack-explained.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2008-October/005360.htmlhttp://marc.info/?l=bugtraq&m=125856010926699&w=2http://searchsecurity.techtarget.com.au/articles/27154-TCP-is-fundamentally-borkedhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080af511d.shtmlhttp://www.cisco.com/en/US/products/products_security_response09186a0080a15120.htmlhttp://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.outpost24.com/news/news-2008-10-02.htmlhttp://www.us-cert.gov/cas/techalerts/TA09-251A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6340https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html
2008-10-20
Published