Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
BID:2799
Info
Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
| Bugtraq ID: | 2799 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2001 12:00AM |
| Updated: | May 29 2001 12:00AM |
| Credit: | Reportedly discovered by James Thomas and published to Bugtraq in a NetBSD Security Advisory on May 29, 2001. |
| Vulnerable: |
NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.4 SPARC NetBSD NetBSD 1.4 arm32 NetBSD NetBSD 1.4 Alpha NetBSD NetBSD 1.4 FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 |
| Not Vulnerable: |
NetBSD NetBSD 1.5.1 |
Discussion
Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
Operating systems derived from BSD contain a vulnerability in the inherited TCP/IP implementation that may lead to possible denial of service conditions.
The problem is that there is no limit to how many IP fragment reassembly queues can be created. A remote attacker may be able to exhaust resources by causing the creation of a large number of reassembly queues.
NetBSD and FreeBSD are vulnerable. OpenBSD and BSDI may also be vulnerable to this attack.
Operating systems derived from BSD contain a vulnerability in the inherited TCP/IP implementation that may lead to possible denial of service conditions.
The problem is that there is no limit to how many IP fragment reassembly queues can be created. A remote attacker may be able to exhaust resources by causing the creation of a large number of reassembly queues.
NetBSD and FreeBSD are vulnerable. OpenBSD and BSDI may also be vulnerable to this attack.
Exploit / POC
Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
Solution:
Systems running NetBSD-current dated from before April 17, 2001 should be upgraded to NetBSD-current dated April 17, 2001 or later.
Systems running NetBSD 1.5.x systems dated from before April 24, 2001 should be upgraded to NetBSD 1.5.x dated April 24, 2001 or later.
NetBSD 1.5.1 will ship with the fix.
There is no fix to 1.4.x available at this time.
FreeBSD has released kernel patches.
FreeBSD FreeBSD 3.0
FreeBSD FreeBSD 3.1
FreeBSD FreeBSD 3.2
FreeBSD FreeBSD 3.3
FreeBSD FreeBSD 3.4
FreeBSD FreeBSD 3.5
FreeBSD FreeBSD 3.5.1
FreeBSD FreeBSD 4.0
FreeBSD FreeBSD 4.1
FreeBSD FreeBSD 4.1.1
FreeBSD FreeBSD 4.2
FreeBSD FreeBSD 4.3
Solution:
Systems running NetBSD-current dated from before April 17, 2001 should be upgraded to NetBSD-current dated April 17, 2001 or later.
Systems running NetBSD 1.5.x systems dated from before April 24, 2001 should be upgraded to NetBSD 1.5.x dated April 24, 2001 or later.
NetBSD 1.5.1 will ship with the fix.
There is no fix to 1.4.x available at this time.
FreeBSD has released kernel patches.
FreeBSD FreeBSD 3.0
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.1
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.2
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.3
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.4
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.5
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 3.5.1
-
FreeBSD 3.x frag-3.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-3.x.patch
FreeBSD FreeBSD 4.0
-
FreeBSD 4.x frag-4.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-4.x.patch
FreeBSD FreeBSD 4.1
-
FreeBSD 4.x frag-4.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-4.x.patch
FreeBSD FreeBSD 4.1.1
-
FreeBSD 4.x frag-4.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-4.x.patch
FreeBSD FreeBSD 4.2
-
FreeBSD 4.x frag-4.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-4.x.patch
FreeBSD FreeBSD 4.3
-
FreeBSD 4.x frag-4.x.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:52/frag-4.x.patch
References
Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability
References:
References:
- FreeBSD Security Information (FreeBSD)
- NetBSD Security Page (NetBSD)