CVE Database
/

CVE-2004-1060

Back to search

CVE-2004-1060

Published: Apr 13, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:181
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:196
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:780
vdb-entry
signature
x_refsource_OVAL
13124
vdb-entry
x_refsource_BID
HPSBUX01164
vendor-advisory
x_refsource_HP
oval:org.mitre.oval:def:3826
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:405
vdb-entry
signature
x_refsource_OVAL
SSRT4743
vendor-advisory
x_refsource_HP
HPSBTU01210
vendor-advisory
x_refsource_HP
oval:org.mitre.oval:def:899
vdb-entry
signature
x_refsource_OVAL
MS05-019
vendor-advisory
x_refsource_MS
SSRT4884
vendor-advisory
x_refsource_HP
18317
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:2188
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:651
vdb-entry
signature
x_refsource_OVAL
19
third-party-advisory
x_refsource_SREASON
57
third-party-advisory
x_refsource_SREASON
oval:org.mitre.oval:def:5386
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now