CVE-2001-0323
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to…
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=97958349623450&w=2
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5975
- http://marc.info/?l=bugtraq&m=97958349623450&w=2
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5975
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.