i5/OS and OS/400 TCP/IP Vulnerability Surfaces
July 16, 2007 Timothy Prickett Morgan
The U.S. Department of Homeland Security may not be able to fill thousands of posts in its organization, but the department’s National Cyber Security Division is on top of things. Last week, the National Vulnerability database maintained by the DHS division reported that there is a vulnerability in several OS/400 and i5/OS releases relating to the TCP/IP stack. According to the report, which you can read here, OS/400 V4R2 through OS/400 V5R3 have a vulnerability in their TCP/IP stack such that when the stack is pinged with TCP SYN-FIN combinations to cause the TCP/IP stack to respond and therefore |