PT-1999-1891 · Openbsd+2 · Openbsd+2
Published
1999-09-05
·
Updated
2017-10-10
·
CVE-2000-0489
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
NetBSD (affected versions not specified)
OpenBSD (affected versions not specified)
Description
The issue allows an attacker to cause a denial of service by creating a large number of socket pairs using the
socketpair function, setting a large buffer size via setsockopt, then writing large buffers.Recommendations
For FreeBSD, consider restricting the use of the
socketpair function until a patch is available.
For NetBSD, restrict access to the setsockopt function to minimize the risk of exploitation.
For OpenBSD, avoid using large buffer sizes via setsockopt in the affected socket pairs until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Netbsd
Openbsd