CVE-2008-1312 |
|
发布时间 :2008-03-12 13:44:00 | ||
修订时间 :2008-10-11 01:51:36 | ||||
NMCO |
[原文]Unspecified vulnerability in the TFTP server in PacketTrap Networks pt360 Tool Suite 1.1.33.1.0, and other versions before 2.0.3900.0, allows remote attackers to cause a denial of service (daemon crash) via a long TFTP packet, a different vulnerability than CVE-2008-1311.
[CNNVD]PacketTrap Networks pt360 Tool Suite 未明TFTP包拒绝服务漏洞(CNNVD-200803-204)
PacketTrap Networks pt360 Tool Suite中的TFTP服务器存在未明漏洞。远程攻击者通过一个长的TFTP信息包来造成拒绝服务。
–
CVSS (基础分值)
CVSS分值: | 5 | [中等(MEDIUM)] |
机密性影响: | NONE | [对系统的机密性无影响] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | PARTIAL | [可能会导致性能下降或中断资源访问] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CPE (受影响的平台与产品)
cpe:/a:packettrap:pt360_tool_suite:1.1.33.1.0 | |
cpe:/a:packettrap:pt360_tool_suite |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://xforce.iss.net/xforce/xfdb/41267 (UNKNOWN) XF pt360-tftpserver-unspecified-dos(41267) |
http://www.securityfocus.com/bid/28079 (UNKNOWN) BID 28079 |
http://www.emediawire.com/releases/2008/2/prweb731563.htm (UNKNOWN) CONFIRM http://www.emediawire.com/releases/2008/2/prweb731563.htm |
http://secunia.com/advisories/29207 (VENDOR_ADVISORY) SECUNIA 29207 |
http://packetstorm.linuxsecurity.com/0803-advisories/DDIVRT-2008-09.txt (UNKNOWN) MISC http://packetstorm.linuxsecurity.com/0803-advisories/DDIVRT-2008-09.txt |
http://marc.info/?l=bugtraq&m=120457979416868&w=2 (UNKNOWN) BUGTRAQ 20080303 DDIVRT-2008-09 PacketTrap PT360 Tool Suite TFTP Denial of Service Vulnerability |
–
漏洞信息
PacketTrap Networks pt360 Tool Suite 未明TFTP包拒绝服务漏洞 | |
中危 | 设计错误 |
2008-03-12 00:00:00 | 2008-10-11 00:00:00 |
远程 | |
PacketTrap Networks pt360 Tool Suite中的TFTP服务器存在未明漏洞。远程攻击者通过一个长的TFTP信息包来造成拒绝服务。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: http://www.packettrap.com |
–
漏洞信息
43060 |
|
PacketTrap pt360 TFTP Server Crafted Packet Remote DoS | |
Remote / Network Access |
Denial of Service |
Loss of Availability | |
Vendor Verified |
–
漏洞描述
–
时间线
2008-03-03 |
2008-01-29 |
Unknow | 2008-02-29 |
–
解决方案
Upgrade to version 2.0.3900.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. |
–
相关参考
|
–
漏洞作者
Unknown or Incomplete |