North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Cisco Vulnerability in a Variant of the TCP Timestamps Option

  • From: trainier
  • Date: Thu May 19 10:26:28 2005


It's a little broader than just cisco equipment.
http://www.securityfocus.com/bid/13676


"Fergie (Paul Ferguson)" <[email protected]>
Sent by: [email protected]

05/19/2005 10:11 AM

To
[email protected]
cc
Subject
Cisco Vulnerability in a Variant of the TCP Timestamps Option







Cisco yesterday reported a vulnerability with some implementations of the Transmission Control Protocol (TCP) Timestamps option (RFC1323) are vulnerable to a Denial of Service (DoS) attack from specifically crafted packets. Cisco also states that only certain implementations of the TCP Timestamps option are vulnerable.

The entire security alert can be found here:
http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml

- ferg

--
"Fergie", a.k.a. Paul Ferguson
Engineering Architecture for the Internet
[email protected] or [email protected]
ferg's tech blog: http://fergdawg.blogspot.com/