CVE-2006-4304
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 11.70% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- freebsd/freebsd · netbsd/netbsd · openbsd/openbsd
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-019.txt.asc
- http://secunia.com/advisories/21587Patch, Vendor Advisory
- http://secunia.com/advisories/21731Patch, Vendor Advisory
- http://security.FreeBSD.org/advisories/FreeBSD-SA-06:18.ppp.ascVendor Advisory
- http://security.FreeBSD.org/patches/SA-06:18/ppp4x.patch
- http://securitytracker.com/id?1016745
- http://www.openbsd.org/errata.html#spppPatch
- http://www.openbsd.org/errata38.html#spppPatch
- http://www.securityfocus.com/bid/19684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28562
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-019.txt.asc
- http://secunia.com/advisories/21587Patch, Vendor Advisory
- http://secunia.com/advisories/21731Patch, Vendor Advisory
- http://security.FreeBSD.org/advisories/FreeBSD-SA-06:18.ppp.ascVendor Advisory
- http://security.FreeBSD.org/patches/SA-06:18/ppp4x.patch
- http://securitytracker.com/id?1016745
- http://www.openbsd.org/errata.html#spppPatch
- http://www.openbsd.org/errata38.html#spppPatch
- http://www.securityfocus.com/bid/19684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28562
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.