NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
BID:8340
Info
NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
| Bugtraq ID: | 8340 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2003 12:00AM |
| Updated: | Aug 04 2003 12:00AM |
| Credit: | This vulnerability was disclosed in a vendor advisory. |
| Vulnerable: |
NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 |
| Not Vulnerable: | |
Discussion
NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
It has been reported that NetBSD systems that have OSI networking support compiled into their kernel are prone to a remote denial of service vulnerability.
The issue exists because error-reporting functions invoked by the netiso enabled kernel, under some circumstances, are not implemented correctly to abide by requisites of the BSD networking stack.
It has been reported that NetBSD systems that have OSI networking support compiled into their kernel are prone to a remote denial of service vulnerability.
The issue exists because error-reporting functions invoked by the netiso enabled kernel, under some circumstances, are not implemented correctly to abide by requisites of the BSD networking stack.
Exploit / POC
NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
Solution:
The vendor has released a security advisory to address this issue:
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2003-05-26 or later.
Users of NetBSD 1.6 dated from before 2003-05-25 are advised to upgrade from NetBSD 1.6 sources dated 2003-05-26 or later.
Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated from before 2003-05-27 should upgrade from NetBSD 1.5.* sources dated 2003-05-28 or later.
Further details are available in the referenced advisory (2003-010).
Solution:
The vendor has released a security advisory to address this issue:
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2003-05-26 or later.
Users of NetBSD 1.6 dated from before 2003-05-25 are advised to upgrade from NetBSD 1.6 sources dated 2003-05-26 or later.
Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated from before 2003-05-27 should upgrade from NetBSD 1.5.* sources dated 2003-05-28 or later.
Further details are available in the referenced advisory (2003-010).
References
NetBSD Kernel OSI Packet Handler Remote Denial Of Service Vulnerability
References:
References: