FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0054

This CVE name corresponds to:

Entered Topic
2006-02-14 ipfw -- IP fragment denial of service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0054
Phase Assigned(20051230)

Description

The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.

References

Source Reference
FREEBSD FreeBSD-SA-06:04
BID 16209
OSVDB 22319
SECTRACK 1015477
SECUNIA 18378
XF ipfw-icmp-fragment-dos(24073)