OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
BID:16375
Info
OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
| Bugtraq ID: | 16375 |
| Class: | Design Error |
| CVE: |
CVE-2006-0381 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2006 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | Jakob Schlyter and Daniel Hartmeier are credited with the discovery of this issue. |
| Vulnerable: |
OpenBSD OpenBSD 3.8 OpenBSD OpenBSD 3.7 OpenBSD OpenBSD -current FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.4-STABLE |
| Not Vulnerable: | |
Discussion
OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
OpenBSD's PF is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that results in a kernel crash when attempting to normalize IP fragments.
This issue allows remote attackers to crash affected kernels, denying further network service to legitimate users.
OpenBSD's PF is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that results in a kernel crash when attempting to normalize IP fragments.
This issue allows remote attackers to crash affected kernels, denying further network service to legitimate users.
Exploit / POC
OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
Solution:
The OpenBSD CVS tree has had fixes applied since 2006-01-19. These fixes are available for OpenBSD 3.7, 3.8, and -current. Patches can be obtained from CVSweb at:
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&r2=1.104
FreeBSD has released an advisory, along with a patch to address this issue. The FreeBSD CVS tree has had fixes applied since 2006-01-25 10:02:27 UTC. Please see the referenced advisory for further information.
FreeBSD FreeBSD 5.4-STABLE
FreeBSD FreeBSD 5.3 -RELEASE
FreeBSD FreeBSD 5.3 -RELENG
FreeBSD FreeBSD 5.3
FreeBSD FreeBSD 5.3 -STABLE
FreeBSD FreeBSD 5.4 -RELEASE
FreeBSD FreeBSD 5.4 -RELENG
FreeBSD FreeBSD 6.0 -RELEASE
FreeBSD FreeBSD 6.0 -STABLE
Solution:
The OpenBSD CVS tree has had fixes applied since 2006-01-19. These fixes are available for OpenBSD 3.7, 3.8, and -current. Patches can be obtained from CVSweb at:
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&r2=1.104
FreeBSD has released an advisory, along with a patch to address this issue. The FreeBSD CVS tree has had fixes applied since 2006-01-25 10:02:27 UTC. Please see the referenced advisory for further information.
FreeBSD FreeBSD 5.4-STABLE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.3 -RELEASE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.3 -RELENG
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.3
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.3 -STABLE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.4 -RELEASE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 5.4 -RELENG
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 6.0 -RELEASE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
FreeBSD FreeBSD 6.0 -STABLE
-
FreeBSD pf.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:07/pf.patch
References
OpenBSD PF IP Fragment Remote Denial Of Service Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- FreeBSD Security Information (FreeBSD)
- OpenBSD Errata Page (OpenBSD)
- OpenBSD Homepage (OpenBSD)
- OpenBSD Security Information (OpenBSD)