20021017 Re: NSSI-2002-zonealarm3: ZoneAlarm Pro Denial of Service Vulnerabilitymailing list
http://archives.neohapsis.com/archives/bugtraq/2002-10/0238.html CVE-2002-1911
Zone Labs ZoneAlarm 3.0/3.1 - Syn Flood Denial of Service
Record summary
CVE-2002-1911 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZone Labs ZoneAlarm 3.0/3.1 - Syn Flood Denial of ServiceExploitDB exploitby Abraham LincolnNot analyzed1 file
References
5zonealarm-synflood-dos(10379)vdb entry
http://www.iss.net/security_center/static/10379.php 20021016 NSSI-2002-zonealarm3: ZoneAlarm Pro Denial of Service Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/295434 5975vdb entry
http://www.securityfocus.com/bid/5975 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1911