CVE-2004-0230: Medium severity Oracle Solaris vulnerability

Published May 5, 2004
·
Updated

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Affected Software

87 affected components
Oracle Solaris=11
Oracle Solaris=10
Openpgp OpenPGP=2.6.2
McAfee Network Data Loss Prevention=9.2.0
McAfee Network Data Loss Prevention<=8.6
McAfee Network Data Loss Prevention=9.2.1
McAfee Network Data Loss Prevention=9.2.2
NetBSD NetBSD=1.5.3
NetBSD NetBSD=1.6
NetBSD NetBSD=1.5
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=1.5.1
NetBSD NetBSD=1.5.2
NetBSD NetBSD=2.0
Xinuos Openserver=5.0.7
Xinuos Openserver=5.0.6
Juniper Junos
Xinuos Unixware=7.1.3
Xinuos Unixware=7.1.1
Juniper Junos<11.4
Juniper Junos=11.4
Juniper Junos=11.4-r1
Juniper Junos=11.4-r10
Juniper Junos=11.4-r2
Juniper Junos=11.4-r3
Juniper Junos=11.4-r4
Juniper Junos=11.4-r5
Juniper Junos=11.4-r6
Juniper Junos=11.4-r7
Juniper Junos=11.4-r8
Juniper Junos=11.4-r9
Juniper Junos=11.4r13-s2
Juniper Junos=11.4x27
Juniper Junos=12.1
Juniper Junos=12.1r
Juniper Junos=12.1x44
Juniper Junos=12.1x44-d10
Juniper Junos=12.1x44-d15
Juniper Junos=12.1x44-d20
Juniper Junos=12.1x44-d25
Juniper Junos=12.1x44-d30
Juniper Junos=12.1x44-d35
Juniper Junos=12.1x45
Juniper Junos=12.1x45-d10
Juniper Junos=12.1x45-d15
Juniper Junos=12.1x45-d20
Juniper Junos=12.1x46
Juniper Junos=12.1x46-d10
Juniper Junos=12.1x46-d15
Juniper Junos=12.1x47
Juniper Junos=12.2
Juniper Junos=12.2-r1
Juniper Junos=12.2-r2
Juniper Junos=12.2-r3
Juniper Junos=12.2-r4
Juniper Junos=12.2-r5
Juniper Junos=12.2-r6
Juniper Junos=12.2-r7
Juniper Junos=12.3
Juniper Junos=12.3-r1
Juniper Junos=12.3-r2
Juniper Junos=12.3-r3
Juniper Junos=12.3-r4
Juniper Junos=12.3-r5
Juniper Junos=13.1
Juniper Junos=13.1-r1
Juniper Junos=13.1-r2
Juniper Junos=13.1-r3
Juniper Junos=13.2
Juniper Junos=13.2-r1
Juniper Junos=13.2-r2
Juniper Junos=13.2-r3
Juniper Junos=13.3
Juniper Junos=13.3-r1
Microsoft Windows 2000=sp3
Microsoft Windows 2000=sp4
Microsoft Windows 98
Microsoft Windows 98SE
Microsoft Windows Server 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows XP
Microsoft Windows XP=sp1
Microsoft Windows XP=sp1
Microsoft Windows XP=sp2

Event History

May 5, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2004-0230?

CVE-2004-0230 is considered a moderate severity vulnerability due to its potential to cause denial of service on persistent TCP connections.

2

How do I fix CVE-2004-0230?

To mitigate CVE-2004-0230, apply security patches provided by your software vendor or consider limiting the TCP window size.

3

Which software versions are affected by CVE-2004-0230?

CVE-2004-0230 affects several versions including Oracle Solaris 10 and 11, OpenPGP 2.6.2, and specific releases of McAfee Network Data Loss Prevention.

4

What type of attack does CVE-2004-0230 facilitate?

CVE-2004-0230 allows attackers to easily guess TCP sequence numbers and inject TCP RST packets, leading to connection loss.

5

Is CVE-2004-0230 a type of DDoS vulnerability?

While CVE-2004-0230 can cause denial of service, it is typically exploited in targeted attacks rather than large-scale distributed denial of service (DDoS) attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203