Vulnerability Name:

CVE-2005-0688 (CCN-19593)

Assigned:2005-03-05
Published:2005-03-05
Updated:2018-10-19
Summary:Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Sat Mar 05 2005 - 12:17:14 CST
Windows Server 2003 and XP SP2 LAND attack vulnerability

Source: MITRE
Type: CNA
CVE-2005-0688

Source: BUGTRAQ
Type: UNKNOWN
20050305 Windows Server 2003 and XP SP2 LAND attack vulnerability

Source: CCN
Type: SA22341
Microsoft Windows Multiple IPv6 Denial of Service Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
22341

Source: CCN
Type: ASA-2006-217
Windows Security Updates for October 2006 - (MS06-056 - MS06-065)

Source: CCN
Type: CIAC INFORMATION BULLETIN P-177
Vulnerabilities in TCP-IP (893066)

Source: CCN
Type: US-CERT VU#396645
Microsoft Windows vulnerable to DoS via LAND attack

Source: CCN
Type: Microsoft Security Bulletin MS05-019
Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial of Service (893066)

Source: CCN
Type: Microsoft Security Bulletin MS06-032
Vulnerability in TCP/IP Could Allow Remote Code Execution (917953)

Source: CCN
Type: Microsoft Security Bulletin MS06-064
Vulnerabilities in TCP/IP IPv6 Could Allow Denial of Service (922819)

Source: CCN
Type: Microsoft Security Bulletin MS08-001
Vulnerabilities in TCP/IP Could Allow Remote Code Execution (941644)

Source: CCN
Type: Microsoft Security Bulletin MS08-004
Vulnerability in Windows TCP/IP Could Allow Denial of Service (946456)

Source: HP
Type: UNKNOWN
SSRT061264

Source: VUPEN
Type: UNKNOWN
ADV-2006-3983

Source: MS
Type: UNKNOWN
MS05-019

Source: MS
Type: UNKNOWN
MS06-064

Source: XF
Type: UNKNOWN
win-server-xp-land-dos(19593)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1288

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1685

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:482

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:4978

Vulnerable Configuration:Configuration 1:
  • cpe:/o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows_98:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_98se:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_me:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp3:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:4978
    V
    Server 2003 Object Management Vulnerability
    2013-09-02
    oval:org.mitre.oval:def:1288
    V
    Win2k Land Vulnerability
    2011-05-16
    oval:org.mitre.oval:def:1685
    V
    WinXP Land Vulnerability
    2011-05-16
    oval:org.mitre.oval:def:482
    V
    Spoofed Connection Request Vulnerability
    2011-05-09
    BACK
    microsoft windows 2003 server r2
    microsoft windows xp * sp2
    microsoft windows 98 *
    microsoft windows 98se *
    microsoft windows me *
    microsoft windows 2000 - sp3
    microsoft windows xp - sp1
    microsoft windows 2000 - sp4
    microsoft windows 2003 server *
    microsoft windows xp sp2
    microsoft windows 2003 server -
    microsoft windows 2003_server
    microsoft windows 2003_server sp1
    microsoft windows 2003_server sp1_itanium