Strike ID:
E13-5if01
CVSS:
4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
False Positive:
t
Variants:
1
Year:
2013

Description

This strike exploits a resource exhaustion vulnerability in Novell Open Enterprise. When a TCP connection to the HTTPSTK service is terminated using a FIN packet, SSL free is not called, causing the connection to remain in the CLOSE WAIT state. An attacker can connect and terminate many connections, eventually exhausting the system resources, resulting in a denial of service condition.

CVE

References

MSB

BID

ExploitDB

Secunia

Security Tracker

Metasploit

ZDI

Google

OSVDB

{100455}