NetBSD ARP Cross Network Vulnerability
BID:264
Info
NetBSD ARP Cross Network Vulnerability
| Bugtraq ID: | 264 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 1999 12:00AM |
| Updated: | May 21 1999 12:00AM |
| Credit: | This vulnerability was discovered by Olaf "Rhialto" Seibert. |
| Vulnerable: |
NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 |
| Not Vulnerable: |
NetBSD NetBSD 1.4 x86 |
Discussion
NetBSD ARP Cross Network Vulnerability
ARP is a protocol used to dynamically obtain Network Layer to Link Layer address tranlation services. A vulnerability in NetBSD's ARP implementation allows rouge hosts attached to a network to which a NetBSD multihomed host is attached to insert ARP table entries for hosts in the other networks to which the NetBSD host is attached. The NetBSD host fails to check the address information of incoming ARP packets to ensure that is corresponds to one of the address of the interface on which the packet arrived.
ARP is a protocol used to dynamically obtain Network Layer to Link Layer address tranlation services. A vulnerability in NetBSD's ARP implementation allows rouge hosts attached to a network to which a NetBSD multihomed host is attached to insert ARP table entries for hosts in the other networks to which the NetBSD host is attached. The NetBSD host fails to check the address information of incoming ARP packets to ensure that is corresponds to one of the address of the interface on which the packet arrived.
Exploit / POC
NetBSD ARP Cross Network Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetBSD ARP Cross Network Vulnerability
Solution:
Upgrade to NetBSD-1.4 or NetBSD-1.4_BETA after 1999-05-05.
A patch is available for NetBSD 1.3.3 to fix this problem. You may find this patch on the NetBSD ftp server:
ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/patches/19990505-arp
NetBSD-current since 19990506 is not vulnerable. Users of NetBSD-current should upgrade to a source tree later than 19990506.
Solution:
Upgrade to NetBSD-1.4 or NetBSD-1.4_BETA after 1999-05-05.
A patch is available for NetBSD 1.3.3 to fix this problem. You may find this patch on the NetBSD ftp server:
ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/patches/19990505-arp
NetBSD-current since 19990506 is not vulnerable. Users of NetBSD-current should upgrade to a source tree later than 19990506.
References
NetBSD ARP Cross Network Vulnerability
References:
References: