NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
BID:19684
CVE-2006-4304 |Info
NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19684 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4304 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2006 12:00AM |
| Updated: | Sep 06 2006 06:13PM |
| Credit: | Pavel Cahyna has been credited with the discovery of these vulnerability. |
| Vulnerable: |
OpenBSD OpenBSD 3.9 OpenBSD OpenBSD 3.8 NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 4,0_Beta NetBSD NetBSD 3,1_RC1 Navision Financials Server 3.0 FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELEASE FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE |
| Not Vulnerable: |
NetBSD NetBSD current August 23 2006 NetBSD NetBSD 3.0.2 NetBSD NetBSD 4.0 NetBSD NetBSD 3.1 NetBSD NetBSD 2.1.1 NetBSD NetBSD 2.0.4 |
Discussion
NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
NetBSD's PPP implementation is prone to multiple remote buffer-overflow vulnerabilities because the software fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
A remote attacker can exploit these issues to crash the affected computer, denying service to legitimate users. Arbitrary code execution is possible, but this has not been confirmed.
NetBSD's PPP implementation is prone to multiple remote buffer-overflow vulnerabilities because the software fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
A remote attacker can exploit these issues to crash the affected computer, denying service to legitimate users. Arbitrary code execution is possible, but this has not been confirmed.
Exploit / POC
NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
Solution:
Multiple vendors have released updates to address these issues. Please see the references for more information.
OpenBSD OpenBSD 3.8
OpenBSD OpenBSD 3.9
Solution:
Multiple vendors have released updates to address these issues. Please see the references for more information.
OpenBSD OpenBSD 3.8
-
OpenBSD 014_sppp.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/014_sppp.patch
OpenBSD OpenBSD 3.9
-
OpenBSD 009_sppp.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/009_sppp.patch
References
NetBSD In-Kernel PPP Multiple Buffer Overflow Vulnerabilities
References:
References:
- FreeBSD Security Page (FreeBSD)