FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-4304

This CVE name corresponds to:

Entered Topic
2006-08-23 sppp -- buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-4304
Phase Assigned(20060822)

Description

Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.

References

Source Reference
FREEBSD FreeBSD-SA-06:08
MISC http://security.FreeBSD.org/patches/SA-06:18/ppp4x.patch
NETBSD NetBSD-SA2006-019
OPENBSD [3.9] 20060902 009: SECURITY FIX: September 2, 2006
OPENBSD [3.8] 20060902 014: SECURITY FIX: September 2, 2006
BID 19684
SECTRACK 1016745
SECUNIA 21587
SECUNIA 21731
XF sppp4-lcp-bo(28562)