PT-2008-5824 · Linux+3 · Linux+6

Jack C. Louis

·

Published

2008-10-20

·

Updated

2026-03-14

·

CVE-2008-4609

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux (affected versions not specified) Microsoft Windows (affected versions not specified) Cisco products (affected versions not specified)
Description A denial of service issue exists due to the way TCP connections are handled, allowing remote attackers to cause connection queue exhaustion via multiple vectors that manipulate information in the TCP state table. This can be achieved by flooding a system with specially crafted packets, causing the affected system to stop responding to new requests or automatically restart. The effect of this issue can be amplified by the requirement to process packets with a TCP receive window size set to a very small value or zero. An attacker must be able to complete a TCP three-way handshake with a vulnerable system to exploit this issue.
Recommendations For Linux, at the moment, there is no information about a newer version that contains a fix for this issue. For Microsoft Windows, at the moment, there is no information about a newer version that contains a fix for this issue. For Cisco products, Cisco has released free software updates for download from the Cisco website that address these issues. Workarounds that mitigate these issues are available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-6513
CVE-2008-4609
ECHO-6EB9-5518-7E24

Affected Products

Cisco Asa
Cisco Ios
Cisco Ios Xe
Cisco Products
Debian
Linux
Windows