CNCVE编号:CNCVE-20010328 CVE编号:CAN-2001-0328 安全级别:高 漏洞中文描述: 初始队列号(ISN)使用随机增量的TCP实施方法,允许远程攻击者通过在ISN值的一定范围内插入大量的包,这些包中只要有一个与预期的ISN相匹配,就能劫持会话或中断会话。 漏洞英文描述: TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. 漏洞参考: CERT:CA-2001-09 URL:http://www.cert.org/advisories/CA-2001-09.html 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple其他 漏洞类型:设计错误