CVE-2008-4609
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
- Affected products
- Cisco Asa, Cisco Ios, Cisco Ios Xe, Cisco Products, Debian, Linux, Windows
- Bsd
- All versions
- Bsdi Bsd Os
- All versions
- Cisco Ios
- All versions
- Fix
- Available
- CVSS 2.0
- 7.1 HIGH
- EPSS
- 32.1% (98th percentile)
- Weakness
- CWE-16
- NVD status
- Modified
- Published
- 2008-10-20
CVE-2008-4609 at NVD
2 known exploits for CVE-2008-4609
Proof-of-concept code and exploit modules indexed by Sploitus