[NEWS] Packeteer PacketShaper Predictable TCP ISN
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 21 May 2007 10:30:54 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Packeteer PacketShaper Predictable TCP ISN
------------------------------------------------------------------------
SUMMARY
Packeteer PacketShaper has been found to be vulnerable to a vulnerability
that allows remote attackers to predict the next ISN number that will be
given by the TCP stack.
DETAILS
Vulnerable Systems:
* Packeteer PacketShaper versions 7.3.0g2 and 7.5.0g1
The TCP/IP stack of Packeteer PacketShaper is generating predictable
initial sequence numbers (ISN): The sequence number is incremented by
128000 per second and by 64000 per connection. (As an example, if the
current SYN/ACK ISN is 319104000 then about six seconds later the ISN is
likely to be 319936000.) This allows an attacker to spoof connections from
trusted clients or launch a DoS attack.
ADDITIONAL INFORMATION
The information has been provided by <mailto:nnposter@xxxxxxxxxxxxx>
nnposter.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] Tomcat Documentation XSS Vulnerabilities
- Next by Date: [EXPL] Visual Basic VersionCompanyName Buffer Overflow
- Previous by thread: [NEWS] Tomcat Documentation XSS Vulnerabilities
- Next by thread: [EXPL] Visual Basic VersionCompanyName Buffer Overflow
- Index(es):
Relevant Pages
- [NT] WinPcap NPF.SYS Local Privilege Escalation Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of an input
validation vulnerability within the NPF.SYS ... Exploitation allows attackers to execute
arbitrary code in kernel context. ... The vulnerable device driver is loaded when WinPcap
is initialized. ... (Securiteam) - [NT] Qualcomm WorldMail IMAP Server Directory Traversal
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Exploitation of a directory
transversal vulnerability in Qualcomm ... WorldMail IMAP Server allows attackers
to read any email stored on the ... (Securiteam) - [NT] OpenView Client Configuration Manager Device Code Execution
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... This vulnerability allows remote
attackers to execute arbitrary code on ... Authentication is not required to exploit this
vulnerability. ... Where 'port' specifies a connect back port on the connecting
client. ... (Securiteam) - [UNIX] SCO UnixWare pkgadd Directory Traversal Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... SCO UnixWare pkgadd Directory
Traversal Vulnerability ... Exploitation allows attackers gain root privileges. ...
Changing the permissions of the pkgadd command to only allow root to ... (Securiteam) - [UNIX] PrinceClan Chess Component File Inclusion
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PrinceClan Chess Component
File Inclusion ... found to contain a vulnerability that allows remote attackers to
cause the ... attackers to execute arbitrary code. ... (Securiteam)