PT-1999-1891 · Openbsd+2 · Openbsd+2
Publicado
1999-09-05
·
Atualizado
2017-10-10
·
CVE-2000-0489
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
NetBSD (affected versions not specified)
OpenBSD (affected versions not specified)
Description
The issue allows an attacker to cause a denial of service by creating a large number of socket pairs using the
socketpair function, setting a large buffer size via setsockopt, then writing large buffers.Recommendations
For FreeBSD, consider restricting the use of the
socketpair function until a patch is available.
For NetBSD, restrict access to the setsockopt function to minimize the risk of exploitation.
For OpenBSD, avoid using large buffer sizes via setsockopt in the affected socket pairs until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Freebsd
Netbsd
Openbsd