PT-2003-1780 · Netbsd · Netbsd

Published

2003-08-05

·

Updated

2008-09-10

·

CVE-2003-0653

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: NetBSD versions 1.6.1 and earlier
Description: The issue concerns the OSI networking kernel in NetBSD, which fails to use a required PKTHDR mbuf when sending certain error responses. This allows remote attackers to cause a denial of service, potentially leading to a kernel panic or crash, by sending specific OSI packets.
Recommendations: For NetBSD versions 1.6.1 and earlier, consider upgrading to a version that includes the necessary fix to prevent the denial of service. As a temporary workaround, restrict access to the OSI networking kernel to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0653

Affected Products

Netbsd