|
Brought to you by:
Suppliers of:
|
|
|
| |
SecureWay is a robust Firewall product developed by IBM that works under the AIX and Windows platform. It is not a full-fledged stateful packet filter, but more like a stateful-inspection with connection-centric deterministic-filtering firewall.
A security problem in the Firewall has been identified. Whenever a flood of malformed TCP packets reaches the SecureWay Firewall, it will be no longer able to respond to legitimate requests (due to high CPU resources consumption). Due to the nature of this attack, a large portion of bandwidth is required. |
| |
Credit:
The information has been provided by Mauro Flores.
|
| |
Vulnerable systems:
* SecureWay 4.2.x on AIX
When an all zeroed flags TCP packet is sent to the SecureWay Firewall, the firewall will take a large amount of processing time for it to determine that the packet is in fact invalid. Because of this, a flood of such forged packets will consume a large amount resources leading to a denial of service attack.
Vendor Response:
IBM was contacted on July 14, 2002. The vendor confirmed the problem and released a fix.
Corrective Action:
Update to SecureWay Firewall 4.2.2 version or install APAR IR49046.
|
|
|
|
|