FreeBSD TCP SACK远程拒绝服务漏洞

漏洞信息详情

FreeBSD TCP SACK远程拒绝服务漏洞

漏洞简介

FreeBSD 5.3和5.4中的选择性确认(SACK)在内存不足时无法正确处理接收到的选择性确认,从而可能使得远程攻击者造成拒绝服务(无限循环)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

FreeBSD FreeBSD 5.4-STABLE

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.3 -RELENG

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.3

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.3 -RELEASE

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.3 -STABLE

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.4 -RELEASE

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.4 -PRERELEASE

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

FreeBSD FreeBSD 5.4 -RELENG

FreeBSD sack.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch

参考网址

来源: OSVDB

名称: 22861

链接:http://www.osvdb.org/22861

来源: BID

名称: 16466

链接:http://www.securityfocus.com/bid/16466

来源: FREEBSD

名称: FreeBSD-SA-06:08

链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:08.sack.asc

来源: XF

名称: bsd-sack-handling-dos(24453)

链接:http://xforce.iss.net/xforce/xfdb/24453

来源: VUPEN

名称: ADV-2006-0409

链接:http://www.frsirt.com/english/advisories/2006/0409

来源: SECTRACK

名称: 1015566

链接:http://securitytracker.com/id?1015566

来源: SREASON

名称: 399

链接:http://securityreason.com/securityalert/399

来源: SECUNIA

名称: 18696

链接:http://secunia.com/advisories/18696

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享