Re: Local DoS on network by unpriviledged user using setsockopt()

From: Lamont Granquist (lamontgat_private)
Date: Wed Sep 08 1999 - 15:07:17 PDT

  • Next message: Gérald Grévren: "[Security] Spoofed Id in Bluestone Sapphire/Web"

    The following do *not* appear to be vulnerable:
    Solaris 2.7
    HP-UX 11.0
    Digital Unix 4.0D
    IRIX 5.3, 6.4
    
    On Fri, 3 Sep 1999, John N Dvorak wrote:
    > BSDI 2.1
    > BSDI 3.1
    > BSDI 4.0
    > BSDI 4.0.1
    > Cobalt Linux (MIPS) - RedHat based
    >
    > All vulnerable.
    >
    > I am testing on other Linux platforms, but I presume all BSD and
    > Linux-based systems are affected.  I have no resources to test this on
    > Solaris, AIX, HP and System-V based systems.
    >
    > I would venture a guess that MacOS X may be vulnerable since I am fairly
    > sure that most of the socket code is lifted directly from BSD.
    >
    > J
    
    --
    Lamont Granquist                       lamontgat_private
    Dept. of Molecular Biotechnology       (206)616-5735  fax: (206)685-7344
    Box 352145 / University of Washington / Seattle, WA 98195
    PGP pubkey: finger lamontgat_private | pgp -fka
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:02:35 PDT