Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 29 Feb 2004 19:03:41 -0600 (CST)
From:      Mike Silbersack <silby@silby.com>
To:        Mike Tancsa <mike@sentex.net>
Cc:        freebsd-security@freebsd.org
Subject:   Re: mbuf vulnerability
Message-ID:  <20040229190101.V13340@odysseus.silby.com>
In-Reply-To: <6.0.3.0.0.20040229182702.07a67a68@209.112.4.2>
References:  <6.0.3.0.0.20040229182702.07a67a68@209.112.4.2>

next in thread | previous in thread | raw e-mail | index | archive | help

On Sun, 29 Feb 2004, Mike Tancsa wrote:

> In
> http://docs.freebsd.org/cgi/mid.cgi?200402260743.IAA18903
>
> it seems RELENG_4 is vulnerable.  Is there any work around to a system that
> has to have ports open ?

There is no way to fix this issue without kernel modifications.  A fix has
been committed to -current, someone on the security team can probably
provide information on when the MFC will be appearing.

On the plus side, you have to establish a TCP connection to make the DoS
happen, so people abusing it can be easily traced.

Mike "Silby" Silbersack



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040229190101.V13340>