SecureScoutLogo.jpg
Ethernet Frame Padding Information Leakage Vulnerability



Go to Vulnerabilities List


General Info


TC: 11028
Description: Ethernet requires that a packet has a minimum size of 56 bytes. In some cases, like ICMP Reply packets, the size to send is less than this minimum ( 20 bytes for the IP header plus 8 bytes for ICMP data ). In such a situation, the packet must be padded as stated by the RFC 1042:

IEEE 802 packets may have a minimum size restriction. When necessary, the data field should be padded (with octets of zero) to meet the IEEE 802 minimum frame size requirements. This padding is not part of the IP datagram and is not included in the total length field of the IP header.

Some drivers allocate memory to make packets. If they fail to clean the memory before using it, it could result in information disclosure.
TC Impact: Gather Info



Specific Operations and Actions:


Vulnerability Publication: January 6, 2003
Advisory Copyright: Ofir Arkin and Josh Anderson
Summary: It is possible to retrieve information by sending small packets to your server.
Risk: Medium
CVSS 2.0 metrics: Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: Partial
Integrity Impact: None
Availability Impact: None
CVSS 2.0 Base Score: 5.0
Vulnerability Impact: Gather Info
Host Impact: Confidential data could be retrieved.
Nature of Remediation: Update the software.
Step required to fix the reported vulnerability:

***** Solution type: Upgrade Software *****

Check with your network card vendor for a fixed version of the driver.



Glossary and References :


References:
* ATSTAKE: A010603-1
http://www.atstake.com/research/advisories/2003/a010603-1.txt
* BUGTRAQ: 20030110 More information regarding Etherleak
http://marc.theaimsgroup.com/?l=bugtraq&m=104222046632243&w=2
* BUGTRAQ: 20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)
http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded
* BUGTRAQ: 20030117 Re: More information regarding Etherleak
http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded
* VULNWATCH: 20030110 More information regarding Etherleak
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
* REDHAT: RHSA-2003:088
http://www.redhat.com/support/errata/RHSA-2003-088.html
* CERT-VN: VU#412115
http://www.kb.cert.org/vuls/id/412115
* REDHAT: RHSA-2003:025
http://www.redhat.com/support/errata/RHSA-2003-025.html
* OSVDB: 9962
http://www.osvdb.org/9962
* OVAL: oval:org.mitre.oval:def:2665
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665
* SECUNIA: 7996
http://secunia.com/advisories/7996
* MISC:
http://www.ietf.org/rfc/rfc1042.txt
* MISC:
http://online.securityfocus.com/bid/6535

CVE Link: CVE-2003-0001
CVE Compatible

Glossary: ICMP
Information Disclosure


© 2003-2010 NexantiS Corporation (www.securescout.com)
SecureScout is a trademark of NexantiS
All Rights Reserved
All products names referenced herein are trademarks of their respective companies

SecureScout products are certified:
CVE Compatible
SANS TOP 20 Compatible
CVSS Compatible (Common Vulnerability Scoring System)