Multiple Vendor TCP Sequence Number Approximation Vulnerability
Risk: High
Symantec Advisory:..."
A vulnerability in TCP implementations has been reported that may permit unauthorized remote users to reset TCP sessions.
The cause of the vulnerability is that affected implementations will accept TCP sequence numbers within a certain range of the expected sequence number for a packet in the session. This will permit a remote attacker to inject a SYN or RST packet into the session, causing it to be reset "
more info ->
http://www.us-cert.gov/cas/techalerts/TA04-111A.htmlMicrosoft's expectedly-weak response to this was "...Windows Sockets call to recv()/send() returns 10058 (WSAESHUTDOWN) or 10053 (WSAECONNABORTED).
The underlying cause has yet to be determined and remains under investigation..."
bollocks, i say !!!!! -JxL
