Release date:
Updated on:
Affected Systems:
NetBSD netbsd4.0
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-1547
NetBSD is a free and highly customizable Unix-like operating system suitable for multiple platforms, from 64-bit AMD Athlon servers and desktop systems to handheld devices and embedded devices.
NetBSD has a security vulnerability. Malicious users can exploit this vulnerability to cause DoS attacks and control affected systems.
This vulnerability is caused by an error in processing compressed IPComp loads. You can cause stack overflow by sending specially crafted packets to the affected server.
<* Source: Tavis Ormandy (taviso@gentoo.org)
Link: http://www.openwall.com/lists/oss-security/2011/04/01/1
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
NetBSD
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.netbsd.org/Security/