J-Security Center

Title: SuSE identd Denial of Service Attack

Severity: LOW

Description:

In the inetd.conf under certain distributions of SuSE Linux the in.identd daemon is started with the -w -t120 option. This means that one identd process waits 120 seconds after answering the first request to answer the next request. If a malicious remote attacker starts a large number of ident requests in a short period of time it will force the target machine to start multiple daemons because the initial daemon is in a time wait state. This can eventually lead the machine to starve itself of memory resulting essentially in a machine halt.

Affected Products:

  • S.u.S.E. Linux 4.4.0
  • S.u.S.E. Linux 4.4.1
  • S.u.S.E. Linux 5.0.0
  • S.u.S.E. Linux 5.1.0
  • S.u.S.E. Linux 5.2.0
  • S.u.S.E. Linux 5.3.0
  • S.u.S.E. Linux 6.0.0
  • S.u.S.E. Linux 6.1.0
  • S.u.S.E. Linux 6.2.0
  • Slackware Linux 3.2.0
  • Slackware Linux 3.6.0

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.