A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a scrub fragment crop or scrub fragment drop-ovl rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 5.3 (including) | 5.3 (including) |
Freebsd | Freebsd | 5.3-release (including) | 5.3-release (including) |
Freebsd | Freebsd | 5.3-releng (including) | 5.3-releng (including) |
Freebsd | Freebsd | 5.3-stable (including) | 5.3-stable (including) |
Freebsd | Freebsd | 5.4-pre-release (including) | 5.4-pre-release (including) |
Freebsd | Freebsd | 5.4-release (including) | 5.4-release (including) |
Freebsd | Freebsd | 5.4-releng (including) | 5.4-releng (including) |
Freebsd | Freebsd | 6.0-release (including) | 6.0-release (including) |
Freebsd | Freebsd | 6.0-stable (including) | 6.0-stable (including) |
Kfreebsd-5 | Ubuntu | dapper | * |
Kfreebsd-5 | Ubuntu | edgy | * |
Kfreebsd-5 | Ubuntu | feisty | * |
Kfreebsd-5 | Ubuntu | gutsy | * |
Kfreebsd-5 | Ubuntu | hardy | * |
Kfreebsd-5 | Ubuntu | intrepid | * |