First published: Sat Dec 17 2005(Updated: )
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.4 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4316 is considered to have a medium severity rating due to its potential to cause denial of service on affected HP-UX systems.
To mitigate CVE-2005-4316, apply any available patches from HPE for the affected versions of HP-UX.
CVE-2005-4316 affects HP-UX versions 11.00, 11.04, 11.11, and 11.23 specifically.
CVE-2005-4316 describes a denial of service attack known as a "Rose Attack" that exploits IP fragment issues.
Yes, CVE-2005-4316 can be exploited remotely by sending small IP fragments that do not form complete packets.