CVE Vulnerabilities

CVE-2008-1335

Published: Mar 13, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.

Affected Software

NameVendorStart VersionEnd Version
NetbsdNetbsd2.0 (including)2.0 (including)
NetbsdNetbsd2.0.1 (including)2.0.1 (including)
NetbsdNetbsd2.0.2 (including)2.0.2 (including)
NetbsdNetbsd2.0.3 (including)2.0.3 (including)
NetbsdNetbsd2.0.4 (including)2.0.4 (including)
NetbsdNetbsd2.1 (including)2.1 (including)
NetbsdNetbsd2.1.1 (including)2.1.1 (including)
NetbsdNetbsd3.0 (including)3.0 (including)
NetbsdNetbsd3.0.1 (including)3.0.1 (including)
NetbsdNetbsd3.0.2 (including)3.0.2 (including)
NetbsdNetbsd3.1 (including)3.1 (including)
NetbsdNetbsd3.1-rc1 (including)3.1-rc1 (including)
NetbsdNetbsd3.1-rc3 (including)3.1-rc3 (including)
Netbsd_currentNetbsd*20071027 (including)

References