Apple Mac OS TCP/IP denial of service

macos-tcp-ip-dos (16946) The risk level is classified as LowLow Risk

Description:

Mac OS is vulnerable to a denial of service attack, caused by a vulnerability in the TCP/IP stack. By sending specially-crafted IP fragments to a vulnerable system, a remote attacker could consume large amounts of system resources.


Consequences:

Denial of Service

Remedy:

Upgrade to the latest version of Mac OS (10.3.5 or later), available from the Apple Downloads Web page. See References.

References:

  • Apple Downloads Web page: Apple - Support - Download.
  • CIAC Information Bulletin O-212: Apple Security Update.
  • BID-10904: Apple Mac OS X 10.3.5 Released - Multiple Vulnerabilities Fixed
  • CVE-2004-0744: The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a Rose Attack that involves sending a subset of small IP fragments that do not form a complete, larger packet.

Platforms Affected:

  • Apple Mac OS X 10.2
  • Apple Mac OS X 10.2.1
  • Apple Mac OS X 10.2.2
  • Apple Mac OS X 10.2.3
  • Apple Mac OS X 10.2.4
  • Apple Mac OS X 10.2.5
  • Apple Mac OS X 10.2.6
  • Apple Mac OS X 10.2.7
  • Apple Mac OS X 10.2.8
  • Apple Mac OS X 10.3
  • Apple Mac OS X 10.3.1
  • Apple Mac OS X 10.3.2
  • Apple Mac OS X 10.3.3
  • Apple Mac OS X 10.3.4
  • Apple Mac OS X Server 10.2
  • Apple Mac OS X Server 10.2.1
  • Apple Mac OS X Server 10.2.2
  • Apple Mac OS X Server 10.2.3
  • Apple Mac OS X Server 10.2.4
  • Apple Mac OS X Server 10.2.5
  • Apple Mac OS X Server 10.2.6
  • Apple Mac OS X Server 10.2.7
  • Apple Mac OS X Server 10.2.8
  • Apple Mac OS X Server 10.3
  • Apple Mac OS X Server 10.3.1
  • Apple Mac OS X Server 10.3.2
  • Apple Mac OS X Server 10.3.3
  • Apple Mac OS X Server 10.3.4

Reported:

Aug 10, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page