FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0381

This CVE name corresponds to:

Entered Topic
2006-02-14 pf -- IP fragment handling panic

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0381
Phase Assigned(20060124)

Description

A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.

References

Source Reference
FREEBSD FreeBSD-SA-06:07
NETBSD NetBSD-SA2006-004
CONFIRM http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&r2=1.104
BID 16375
OSVDB 22732
SECTRACK 1015542
SECUNIA 18609
XF bsd-pf-fragment-dos(24337)