Improper input validation in NetBSD - #VU12426

 

Improper input validation in NetBSD - #VU12426

Published: May 8, 2018 / Updated: May 10, 2018


Vulnerability identifier: #VU12426
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to a miscomputation in an IPsec function in charge of handling mbufs that results in the wrong length being stored in the mbuf header. A remote attacker can send specially crafted data and cause the service to crash when at least ESP is active.

Affected software

NetBSD

Remediation

Install update from vendor's website.


External References

Related Security Bulletins