Executive brief
Network Flight Recorder (NFR) is a network monitoring and intrusion detection system used to analyze traffic for security threats. A vulnerability in versions 1.5 and 1.6 allows a remote attacker to crash the monitoring service by sending a specially crafted network packet. This results in a denial of service, effectively blinding the security system and preventing it from detecting other malicious activity on the network.
Technical details
A denial of service vulnerability exists in the nfrd daemon of Network Flight Recorder (NFR) versions 1.5 and 1.6. The flaw is triggered when the engine processes a malformed TCP packet characterized by a null header and null data field. An unauthenticated remote attacker can exploit this by sending such a packet to the monitored network, causing the nfrd process to crash. This stops all network traffic recording and analysis. A patch was reportedly made available via SecurityFocus (BID 63) to address the issue.
Affected products
- Network Flight Recorder Network Flight Recorder (NFR) 1.5, 1.6
Timeline
- 1998-04-08: disclosed
- 1998-04-08: advisory: NVD published date