Memory corruption in NetBSD - #VU12431

 

Memory corruption in NetBSD - #VU12431

Published: May 8, 2018 / Updated: May 10, 2018


Vulnerability identifier: #VU12431
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The weakness exists due to a memory leak and use-after-free memory error. A remote attacker can trigger memory corruption and cause the service to crash when both IPv6 and forwarding are enabled.

Affected software

NetBSD

Remediation

Install update from vendor's website.


External References

Related Security Bulletins