PT-2003-1780 · Netbsd · Netbsd
Published
2003-08-05
·
Updated
2008-09-10
·
CVE-2003-0653
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
NetBSD versions 1.6.1 and earlier
Description:
The issue concerns the OSI networking kernel in NetBSD, which fails to use a required
PKTHDR mbuf when sending certain error responses. This allows remote attackers to cause a denial of service, potentially leading to a kernel panic or crash, by sending specific OSI packets.Recommendations:
For NetBSD versions 1.6.1 and earlier, consider upgrading to a version that includes the necessary fix to prevent the denial of service. As a temporary workaround, restrict access to the OSI networking kernel to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbsd