>> Multiple Vendor TCP Timestamps Option Remote Denial of Service
Title : Multiple Vendor TCP Timestamps Option Remote Denial of Service VUPEN ID : VUPEN/ADV-2005-0567 CVE ID : CVE-2005-0356 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-18
Technical Description
A new vulnerability was identified in multiple vendors' operating systems, which may be exploited by remote attackers to cause a denial of service. This flaw resides in the Transmission Control Protocol (TCP) Timestamps and Protection Against Wrapped Sequence Numbers (PAWS) techniques when handling specially crafted segments containing a large timestamp value.
An attacker who is able to determine the source and destination ports and IP addresses of two hosts engaged in an active connection, could exploit this issue to cause a denial of service (DoS) by injecting a specially crafted segment into the connection.