PT-2006-4097 · Netbsd · Netbsd

Christian Biere

·

Published

2006-06-23

·

Updated

2017-07-20

·

CVE-2006-3202

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 2.0 through 3.0
Description The issue concerns the ip6 savecontrol function, which under certain configurations, fails to check if IPv4-mapped sockets are being used before processing IPv6 socket options. This allows local users to cause a denial of service by creating an IPv4-mapped IPv6 socket with the SO TIMESTAMP socket option set and then sending an IPv4 packet through the socket.
Recommendations For NetBSD versions 2.0 through 3.0, consider disabling the use of IPv4-mapped sockets or restricting the SO TIMESTAMP socket option to prevent exploitation until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3202

Affected Products

Netbsd