CVE-2005-4316

HP-UX B.11.00 B.11.04 B.11.11 B.11.23 - Denial of Service via Rose Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2005-4316. PoCs published by Ken Hollis, Coolio.

AI-analyzed exploit summary This exploit implements the 'Rose Attack' (a variation of the 'New Dawn attack') to perform a remote denial-of-service (DoS) by sending highly fragmented TCP or UDP packets, causing high CPU utilization on vulnerable systems. It leverages the netwib library to craft and send malformed packets with configurable fragmentation parameters.

Description

HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Ken Hollis · cdoswindows
https://www.exploit-db.com/exploits/24637

This exploit implements the 'Rose Attack' (a variation of the 'New Dawn attack') to perform a remote denial-of-service (DoS) by sending highly fragmented TCP or UDP packets, causing high CPU utilization on vulnerable systems. It leverages the netwib library to craft and send malformed packets with configurable fragmentation parameters.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple vendor TCP/IP stacks (e.g., Microsoft Windows 2000/XP, Linux kernel 2.4, undisclosed Cisco systems)
No auth needed
Prerequisites: Network access to the target · netwib library installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Ken Hollis · cdoswindows
https://www.exploit-db.com/exploits/24636

This exploit implements the 'New Dawn' attack, a variation of the 'Rose Attack,' which targets inefficiencies in TCP/IP stack handling of fragmented packets to cause a denial-of-service (DoS). It sends highly fragmented TCP or UDP packets with configurable parameters to overwhelm the target system.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple vendor TCP/IP stacks (e.g., Microsoft Windows 2000/XP, Linux kernel 2.4, undisclosed Cisco systems)
No auth needed
Prerequisites: Network access to the target · Ability to send raw packets
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Coolio · cdoswindows
https://www.exploit-db.com/exploits/24635

This exploit targets a TCP/IP stack vulnerability (CVE-2005-4316) by sending fragmented ICMP packets to trigger a denial-of-service condition. It uses raw sockets to craft and send malformed packets with overlapping fragments, exhausting system resources.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple vendor TCP/IP stacks (e.g., Microsoft Windows 2000/XP, Linux kernel 2.4, Cisco systems)
No auth needed
Prerequisites: Raw socket permissions · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Coolio · cdoswindows
https://www.exploit-db.com/exploits/24634

This exploit targets a denial-of-service vulnerability in multiple TCP stack implementations by sending fragmented ICMP packets to trigger inefficient reassembly, leading to resource exhaustion. It is a variation of the 'Rose Attack' and affects systems like Microsoft Windows 2000/XP and Linux kernel 2.4.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple vendor TCP stacks (e.g., Microsoft Windows 2000/XP, Linux kernel 2.4, undisclosed Cisco systems)
No auth needed
Prerequisites: Network access to the target · Raw socket permissions
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015361
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2945
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/419594/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/376490
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19086
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18082/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11258
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5760

Scores

EPSS 0.0659
EPSS Percentile 93.0%

Details

Status published
Products (4)
hp/hp-ux 11.00
hp/hp-ux 11.4
hp/hp-ux 11.11
hp/hp-ux 11.23
Published Dec 17, 2005
Tracked Since Feb 18, 2026