PT-2011-3208 · Netbsd · Netbsd

Tavis Ormandy

·

Publicado

2011-05-09

·

Atualizado

2011-09-07

·

CVE-2011-1547

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NetBSD versions 4.0, 5.0 through 5.0.2, and 5.1 through 5.1.0
Description The issue is related to multiple stack consumption vulnerabilities in the kernel when IPsec is enabled. This can be exploited by remote attackers via crafted IPv4 or IPv6 packets with nested IPComp headers, potentially leading to a denial of service, memory corruption, and panic, or possibly having other unspecified impacts.
Recommendations For NetBSD version 4.0, update to a newer version to mitigate the risk. For NetBSD versions 5.0 through 5.0.2, update to version 5.0.3 or later. For NetBSD versions 5.1 through 5.1.0, update to version 5.1.1 or later.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1547

Produtos afetados

Netbsd