E13-5if01
CVSS:
4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
False Positive:
t
Variants:
1
Year:
2013
Description
This strike exploits a resource exhaustion vulnerability in Novell Open Enterprise. When a TCP connection to the HTTPSTK service is terminated using a FIN packet, SSL free is not called, causing the connection to remain in the CLOSE WAIT state. An attacker can connect and terminate many connections, eventually exhausting the system resources, resulting in a denial of service condition.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{100455}