CVE-2001-1244
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
- Affected products
- Freebsd, Hp-Ux, Linux Kernel, Netbsd, Openbsd, Sunos, Vvos, Windows 2000
- Freebsd
- = 4.3
- Hp Hp-ux
- = 11.00, 11.0.4, 11.11
- Hp Vvos
- = 11.04
- Linux Linux Kernel
- = 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5
- Microsoft Windows 2000
- All versions
- Microsoft Windows Nt
- = 4.0
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 22.0% (97th percentile)
- NVD status
- Modified
- Published
- 2002-05-03
CVE-2001-1244 at NVD
1 known exploit for CVE-2001-1244
Proof-of-concept code and exploit modules indexed by Sploitus