CVE-2004-0230: Medium severity Oracle Solaris vulnerability
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0230?
CVE-2004-0230 is considered a moderate severity vulnerability due to its potential to cause denial of service on persistent TCP connections.
How do I fix CVE-2004-0230?
To mitigate CVE-2004-0230, apply security patches provided by your software vendor or consider limiting the TCP window size.
Which software versions are affected by CVE-2004-0230?
CVE-2004-0230 affects several versions including Oracle Solaris 10 and 11, OpenPGP 2.6.2, and specific releases of McAfee Network Data Loss Prevention.
What type of attack does CVE-2004-0230 facilitate?
CVE-2004-0230 allows attackers to easily guess TCP sequence numbers and inject TCP RST packets, leading to connection loss.
Is CVE-2004-0230 a type of DDoS vulnerability?
While CVE-2004-0230 can cause denial of service, it is typically exploited in targeted attacks rather than large-scale distributed denial of service (DDoS) attacks.