PT-2006-2788 · Netbsd · Netbsd

Published

2006-04-18

·

Updated

2017-07-20

·

CVE-2006-1797

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NetBSD-current versions prior to September 28, 2005
Description The issue allows local users to cause a system crash by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, resulting in a NULL pointer dereference.
Recommendations For NetBSD-current versions prior to September 28, 2005, update to a version released after September 28, 2005 to resolve the issue. As a temporary workaround, consider restricting access to the SIOCGIFALIAS ioctl to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1797

Affected Products

Netbsd