CVE-2006-4304
Summary
| CVE | CVE-2006-4304 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-24 01:04:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Freebsd | Freebsd | 4.11 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.3 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.5 | All | All | All |
| Operating System | Freebsd | Freebsd | 6.0 | All | All | All |
| Operating System | Freebsd | Freebsd | 6.1 | All | All | All |
| Operating System | Freebsd | Freebsd | 4.11 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.3 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.4 | All | All | All |
| Operating System | Freebsd | Freebsd | 5.5 | All | All | All |
| Operating System | Freebsd | Freebsd | 6.0 | All | All | All |
| Operating System | Freebsd | Freebsd | 6.1 | All | All | All |
| Operating System | Netbsd | Netbsd | 2.0 | All | All | All |
| Operating System | Netbsd | Netbsd | 3.0 | All | All | All |
| Operating System | Netbsd | Netbsd | 4.0 | All | All | All |
| Operating System | Netbsd | Netbsd | 2.0 | All | All | All |
| Operating System | Netbsd | Netbsd | 3.0 | All | All | All |
| Operating System | Netbsd | Netbsd | 4.0 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.8 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.9 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.8 | All | All | All |
| Operating System | Openbsd | Openbsd | 3.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| FreeBSD "sppp" Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities | BID | www.securityfocus.com | |
| FreeBSD-SA-06:08 | FREEBSD | security.FreeBSD.org | Vendor Advisory |
| SecurityTracker.com Archives - BSD UNIX PPP LCP Options Length Buffer Overflow Lets Remote Users Deny Service | SECTRACK | securitytracker.com | |
| OpenBSD update for sppp - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| NetBSD-SA2006-019 | NETBSD | ftp.netbsd.org | |
| security.FreeBSD.org/patches/SA-06:18/ppp4x.patch | MISC | security.FreeBSD.org | |
| OpenBSD 4.0 errata | OPENBSD | www.openbsd.org | Patch |
| OpenBSD 3.8 errata | OPENBSD | www.openbsd.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.