PT-2008-5824 · Linux+3 · Linux+6
Jack C. Louis
·
Published
2008-10-20
·
Updated
2026-03-14
·
CVE-2008-4609
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux (affected versions not specified)
Microsoft Windows (affected versions not specified)
Cisco products (affected versions not specified)
Description
A denial of service issue exists due to the way TCP connections are handled, allowing remote attackers to cause connection queue exhaustion via multiple vectors that manipulate information in the TCP state table. This can be achieved by flooding a system with specially crafted packets, causing the affected system to stop responding to new requests or automatically restart. The effect of this issue can be amplified by the requirement to process packets with a TCP receive window size set to a very small value or zero. An attacker must be able to complete a TCP three-way handshake with a vulnerable system to exploit this issue.
Recommendations
For Linux, at the moment, there is no information about a newer version that contains a fix for this issue.
For Microsoft Windows, at the moment, there is no information about a newer version that contains a fix for this issue.
For Cisco products, Cisco has released free software updates for download from the Cisco website that address these issues. Workarounds that mitigate these issues are available.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ios
Cisco Ios Xe
Cisco Products
Debian
Linux
Windows