Vulnerability Name: | CVE-2005-4316 (CCN-24832) | ||||||||
Assigned: | 2005-12-09 | ||||||||
Published: | 2005-12-09 | ||||||||
Updated: | 2018-10-19 | ||||||||
Summary: | HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-4316 Source: CCN Type: SA18082 HP-UX TCP/IP "Rose Attack" Denial of Service Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 18082 Source: CCN Type: SA19086 Avaya PDS HP-UX TCP/IP "Rose Attack" Denial of Service Source: SECUNIA Type: UNKNOWN 19086 Source: CCN Type: SECTRACK ID: 1015361 HP-UX TCP/IP Stack May Consume Excessive System Resources When Under IP Fragment Attacks Source: SECTRACK Type: Patch 1015361 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-062.htm Source: CCN Type: ASA-2006-062 HP-UX running TCP/IP Remote Denial of Service (DoS) (HPSBUX02087) Source: CCN Type: ASA-2006-228 HP-UX running TCP/IP Remote Denial of Service (DoS) Source: BUGTRAQ Type: UNKNOWN 20040927 IPv4 fragmentation --> The Rose Attack Source: HP Type: UNKNOWN SSRT4728 Source: BID Type: UNKNOWN 11258 Source: CCN Type: BID-11258 Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-2945 Source: CCN Type: Hewlett-Packard Company Security Bulletin HPSBUX02087 SSRT4728 rev.1 - HP-UX running TCP/IP Remote Denial of Service (DoS) Source: XF Type: UNKNOWN hpux-ip-fragment-dos(24832) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5760 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |