Description
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
Product(s):
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 SP4 (French)
- Microsoft windows 2000_sp3
- Microsoft Windows 2000 Service Pack 3 Advanced Server Edition
- Microsoft Windows 2000 Service Pack 3 Datacenter Server Edition
- Microsoft Windows 2000 Service Pack 3 Professional Edition
- Microsoft Windows 2000 Service Pack 3 Server Edition
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Datacenter Server SP3
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Service Pack 4 French
- Microsoft Windows 2003 Server R2
- Microsoft Windows 98 Gold
- Microsoft windows 98_gold
- Microsoft Windows 98SE
- Microsoft windows 98_se
- Microsoft Windows ME
- Microsoft windows me_gold
- Microsoft Windows Millenium Edition SCD
- Microsoft Windows XP 64-bit
- Microsoft Windows XP SP1 64-bit
- Microsoft Windows XP Tablet PC Service Pack 1
- Microsoft Windows XP SP2 Tablet PC
- Microsoft windows xp_sp1 tablet_pc
- Microsoft windows xp_sp2 tablet_pc
- Sun Solaris 10.0 on Sparc
- Sun Solaris 9.0 on SPARC
- Sun Microsystems Solaris 7
- Sun SunOS (Solaris 8) 5.8
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-0790, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-0790 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.