FreeBSD TCP SACK Remote Denial Of Service Vulnerability
BID:16466
Info
FreeBSD TCP SACK Remote Denial Of Service Vulnerability
| Bugtraq ID: | 16466 |
| Class: | Design Error |
| CVE: |
CVE-2006-0433 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2006 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | Scott Wood discovered this issue. |
| Vulnerable: |
FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.4-STABLE |
| Not Vulnerable: | |
Discussion
FreeBSD TCP SACK Remote Denial Of Service Vulnerability
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that potentially results in an infinite-loop condition when handling TCP SACK packets.
This issue allows remote attackers to cause affected kernels to enter into an infinite loop, denying further network service to legitimate users.
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that potentially results in an infinite-loop condition when handling TCP SACK packets.
This issue allows remote attackers to cause affected kernels to enter into an infinite loop, denying further network service to legitimate users.
Exploit / POC
FreeBSD TCP SACK Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
FreeBSD TCP SACK Remote Denial Of Service Vulnerability
Solution:
FreeBSD has released an advisory, along with a patch to address this issue. The FreeBSD CVS tree has had fixes applied since 2006-02-01 19:43:36 UTC. Please see the referenced advisory for further information.
FreeBSD FreeBSD 5.4-STABLE
FreeBSD FreeBSD 5.3 -RELENG
FreeBSD FreeBSD 5.3
FreeBSD FreeBSD 5.3 -RELEASE
FreeBSD FreeBSD 5.3 -STABLE
FreeBSD FreeBSD 5.4 -RELEASE
FreeBSD FreeBSD 5.4 -PRERELEASE
FreeBSD FreeBSD 5.4 -RELENG
Solution:
FreeBSD has released an advisory, along with a patch to address this issue. The FreeBSD CVS tree has had fixes applied since 2006-02-01 19:43:36 UTC. Please see the referenced advisory for further information.
FreeBSD FreeBSD 5.4-STABLE
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.3 -RELENG
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.3
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.3 -RELEASE
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.3 -STABLE
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.4 -RELEASE
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.4 -PRERELEASE
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
FreeBSD FreeBSD 5.4 -RELENG
-
FreeBSD sack.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-06:08/sack.patch
References
FreeBSD TCP SACK Remote Denial Of Service Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- FreeBSD Security Information (FreeBSD)