Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Denial of Service >> Zebedee Target Port 0 Denial of Service Vulnerability


Vulnerability Assessment Details

Zebedee Target Port 0 Denial of Service Vulnerability

Vulnerability Assessment Summary
Checks for target port 0 denial of service vulnerability in Zebedee

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote host contains a IP tunnelling programming that is prone to
denial of service attacks.

Description :

The remote host is running Zebedee, an open-source IP tunneling
program for Linux, unix, and Windows.

The version of Zebedee installed on the remote host is prone to denial
of service attacks. Specifically, the server will crash if it
receives a request for a connection with a destination port of 0. By
exploiting this flaw, a possible hacker could cause the affected application
to fail to respond to further requests.

See also :

http://www.securityfocus.com/archive/1/410157/30/0/threaded
http://sourceforge.net/mailarchive/forum.php?thread_id=8134987&forum_id=2055

Solution :

Upgrade to Zebedee 2.4.1A / 2.5.3 or later.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:N/A:P/I:N/B:A)

Networks Security ID: 14796

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors

Cisco WS-C2960-24PC-S 24-Port LAN Lite PoE Managed Switch
$39.99
Cisco WS-C2960-24PC-S 24-Port LAN Lite PoE Managed Switch pictureCISCO WS-C2960S-48FPS-L V03 CATALYST 2960 POE 48-PORT ETHERNET SWITCH W/C2960S-
$119.99
CISCO WS-C2960S-48FPS-L V03  CATALYST 2960 POE 48-PORT ETHERNET SWITCH W/C2960S- pictureCisco WS-C2960-24PC-L 24 port switch
$39.95
Cisco WS-C2960-24PC-L 24 port switch pictureCisco Catalyst 2960-S Series WS-C2960S-24TS-L V02 24-Port Switch C2960S-STACK
$69.99
Cisco Catalyst 2960-S Series WS-C2960S-24TS-L V02 24-Port Switch C2960S-STACK picture


Discussions

No Discussions have been posted on this vulnerability.