Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Denial of Service >> Zebedee Target Port 0 Denial of Service Vulnerability


Vulnerability Assessment Details

Zebedee Target Port 0 Denial of Service Vulnerability

Vulnerability Assessment Summary
Checks for target port 0 denial of service vulnerability in Zebedee

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote host contains a IP tunnelling programming that is prone to
denial of service attacks.

Description :

The remote host is running Zebedee, an open-source IP tunneling
program for Linux, unix, and Windows.

The version of Zebedee installed on the remote host is prone to denial
of service attacks. Specifically, the server will crash if it
receives a request for a connection with a destination port of 0. By
exploiting this flaw, a possible hacker could cause the affected application
to fail to respond to further requests.

See also :

http://www.securityfocus.com/archive/1/410157/30/0/threaded
http://sourceforge.net/mailarchive/forum.php?thread_id=8134987&forum_id=2055

Solution :

Upgrade to Zebedee 2.4.1A / 2.5.3 or later.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:N/A:P/I:N/B:A)

Networks Security ID: 14796

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors

ADVA EtherJack FSP 150CC FSP150CC-GE114 Ethernet Demarcation Network Switch
$114.99
ADVA EtherJack FSP 150CC FSP150CC-GE114 Ethernet Demarcation Network Switch pictureDell PowerConnect 6224 24 Port Gigabit Managed Switch TK308 w Stacking Module
$99.99
Dell PowerConnect 6224 24 Port Gigabit Managed Switch TK308 w Stacking Module pictureWestern Digital WD Livewire Powerline Adapter AV Network Switch Kit 4-Ports
$29.95
Western Digital WD Livewire Powerline Adapter AV Network Switch Kit 4-Ports pictureUsed Cisco C9300-48U-E 9300-48U-E Catalyst Switch
$3450.0
Used Cisco C9300-48U-E 9300-48U-E Catalyst Switch picture


Discussions

No Discussions have been posted on this vulnerability.