PT-2006-4097 · Netbsd · Netbsd

Christian Biere

·

Publicado

2006-06-23

·

Atualizado

2017-07-20

·

CVE-2006-3202

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 2.0 through 3.0
Description The issue concerns the ip6 savecontrol function, which under certain configurations, fails to check if IPv4-mapped sockets are being used before processing IPv6 socket options. This allows local users to cause a denial of service by creating an IPv4-mapped IPv6 socket with the SO TIMESTAMP socket option set and then sending an IPv4 packet through the socket.
Recommendations For NetBSD versions 2.0 through 3.0, consider disabling the use of IPv4-mapped sockets or restricting the SO TIMESTAMP socket option to prevent exploitation until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3202

Produtos afetados

Netbsd