NetBSD IPSec Policy Bypass Vulnerability
BID:28045
Info
NetBSD IPSec Policy Bypass Vulnerability
| Bugtraq ID: | 28045 |
| Class: | Design Error |
| CVE: |
CVE-2008-1335 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Karl Knutsson is credited with the discovery of this vulnerability. |
| Vulnerable: |
NetBSD NetBSD 3.0.2 NetBSD NetBSD 3.0.1 NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD Current NetBSD NetBSD 3.1_RC3 NetBSD NetBSD 3.1 NetBSD NetBSD 3,1_RC1 NetBSD NetBSD 2.0.4 Navision Financials Server 3.0 |
| Not Vulnerable: | |
Discussion
NetBSD IPSec Policy Bypass Vulnerability
NetBSD IPSec is prone to a vulnerability that may allow an attacker to bypass policy restrictions.
This issue affects NetBSD kernels with the 'FAST_IPSEC' option enabled.
NetBSD IPSec is prone to a vulnerability that may allow an attacker to bypass policy restrictions.
This issue affects NetBSD kernels with the 'FAST_IPSEC' option enabled.
Exploit / POC
NetBSD IPSec Policy Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetBSD IPSec Policy Bypass Vulnerability
Solution:
The vendor has released an updated kernel to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released an updated kernel to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.