[原文]IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

[CNNVD]IBM AIX空TCP标记数据包淹没远程拒绝服务攻击漏洞(CNNVD-200210-303)


CVSS分值: 5 [中等(MEDIUM)]
- CPE (受影响的平台与产品)

cpe:/o:ibm:aix:5IBM AIX 5
cpe:/o:ibm:aix:4.3.3IBM AIX 4.3.3

(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

(UNKNOWN)  BUGTRAQ  20021009 Flood ACK packets cause AIX DoS
(VENDOR_ADVISORY)  XF  aix-tcp-flood-dos(10326)
(UNKNOWN)  BID  5925

IBM AIX空TCP标记数据包淹没远程拒绝服务攻击漏洞
- 公告与补丁

        根据报告,IBM APAR IY31641补丁和APAR IY31940补丁分别可使用在AIX 4.3和AIX 5系统上,不过没有得到供应商证实。

IBM AIX Malformed TCP Packet Saturation DoS
IBM AIX Remote Empty TCP Flag Flood Denial Of Service Vulnerability
Vulnerability discovery credited to Mauro Flores <> and Guillermo Freire <>.

- 漏洞讨论

AIX is a variant of the Unix Operating System distributed and maintained by IBM.

It has been reported that AIX does not properly handle malformed TCP packets. When an AIX system receives a TCP packet without flags set, it allocates a memory buffer to the packet and stores it in memory for an arbitrary length of time. By sending a large amount of this type of data, an attacker could crash a vulnerable AIX system.

- 漏洞利用

- 解决方案

IBM has made a fix available for 4.3 series AIX:

