NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101258887105690&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=101258281818524&w=2 | mailing list |
http://online.securityfocus.com/archive/1/254268 | mailing list vendor advisory |
http://www.iss.net/security_center/static/8057.php | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/4015 | vdb entry patch vendor advisory |