CVE-2006-0752: Medium severity Niels Provos Honeyd vulnerability
Published Feb 18, 2006
·Updated
Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.
Affected Software
10 affected components
Niels Provos Honeyd=1.5a
Niels Provos Honeyd=1.0
Niels Provos Honeyd=0.5
Niels Provos Honeyd=0.8b
Niels Provos Honeyd=0.7
Niels Provos Honeyd=0.8a
Niels Provos Honeyd=0.8
Niels Provos Honeyd=0.6a
Niels Provos Honeyd=0.6
Niels Provos Honeyd=0.7a
Remediation
Patch Available
Event History
Feb 18, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0752?
CVE-2006-0752 is considered a medium severity vulnerability as it allows attackers to identify simulated IP addresses.
2
How do I fix CVE-2006-0752?
To fix CVE-2006-0752, upgrade to Honeyd version 1.5 or later that addresses this issue.
3
Which versions of Honeyd are affected by CVE-2006-0752?
CVE-2006-0752 affects Honeyd versions 0.5, 0.6, 0.7, 0.8a, 0.8b, and 1.5a.
4
What types of attacks does CVE-2006-0752 allow?
CVE-2006-0752 allows remote attackers to identify IP addresses being simulated, which could lead to further attacks.
5
Is CVE-2006-0752 easy to exploit?
Yes, CVE-2006-0752 can be exploited by sending illegal IP packet fragments to the vulnerable Honeyd instances.