BSD TCP/IP Broadcast Connection Check Vulnerability
BID:4309
Info
BSD TCP/IP Broadcast Connection Check Vulnerability
| Bugtraq ID: | 4309 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2002 12:00AM |
| Updated: | Mar 18 2002 12:00AM |
| Credit: | Reported by Crist J. Clark <[email protected]>, with credit given to Igor M Podlesny <[email protected]> and Ruslan Ermilov <[email protected]>. |
| Vulnerable: |
SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 2.0 OpenBSD OpenBSD 3.0 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 sh3 NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0 |
| Not Vulnerable: |
SGI IRIX 6.5.17 Apple Mac OS X 10.1.4 |
Discussion
BSD TCP/IP Broadcast Connection Check Vulnerability
An error has been reported in the TCP/IP implementation of multiple BSD derived operating systems, including FreeBSD, NetBSD and possibly OpenBSD. Versions of SGI IRIX are also affected.
RFC 1122 specifies that a TCP implementation must silently discard an incoming SYN segment addressed to a multicast or broadcast address. The vulnerable BSD implementation will drop a packet based on the link layer address, but does not check the destination IP address.
An error has been reported in the TCP/IP implementation of multiple BSD derived operating systems, including FreeBSD, NetBSD and possibly OpenBSD. Versions of SGI IRIX are also affected.
RFC 1122 specifies that a TCP implementation must silently discard an incoming SYN segment addressed to a multicast or broadcast address. The vulnerable BSD implementation will drop a packet based on the link layer address, but does not check the destination IP address.
Solution / Fix
BSD TCP/IP Broadcast Connection Check Vulnerability
Solution:
A patch has been committed to FreeBSD 5-CURRENT as of Feburary 25th, 2002. Patches for OpenBSD and NetBSD have been contributed by "Crist J. Clark" <[email protected]>, and are available in his message in the references section of this advisory.
itojun <[email protected]> has reported that this issue is resolved in the current code base for both OpenBSD and NetBSD.
This vulnerability is present in SGI IRIX releases prior to 6.5.17. Users are advised to upgrade to SGI IRIX 6.5.17 or later, especially those running versions earlier than 6.5.x.
Apple Mac OS X 10.1.3
Solution:
A patch has been committed to FreeBSD 5-CURRENT as of Feburary 25th, 2002. Patches for OpenBSD and NetBSD have been contributed by "Crist J. Clark" <[email protected]>, and are available in his message in the references section of this advisory.
itojun <[email protected]> has reported that this issue is resolved in the current code base for both OpenBSD and NetBSD.
This vulnerability is present in SGI IRIX releases prior to 6.5.17. Users are advised to upgrade to SGI IRIX 6.5.17 or later, especially those running versions earlier than 6.5.x.
Apple Mac OS X 10.1.3
-
Apple MacOSXUpdate10.1.4.dmg.bin
MacOS 10.1.4 update. MacOS 10.1.3 is required.
http://download.info.apple.com/Mac_OS_X/082-0055.20020412/2z/MacOSXUpd ate10.1.4.dmg.bin
References
BSD TCP/IP Broadcast Connection Check Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)
- Mac OS X Update 10.1.4: Information and Download (Apple)
- NetBSD Homepage (NetBSD)
- OpenBSD Homepage (OpenBSD)
- Problem Report misc/35022: network broadcast addresses may be used for communica (FreeBSD)