CVE-2006-4304 (CNNVD-200608-382)
中文标题:
NetBSD PPP驱动远程溢出漏洞
英文标题:
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 2...
漏洞描述
中文描述:
NetBSD是一款免费开放源代码的UNIX性质的操作系统。 在处理从远程主机所接收到的连接控制协议(LCP)配置选项时,ppp(4)没有正确的验证选项长度,这可能导致在所分配的内核内存缓冲区以外读取或写入数据。 能够发送LCP报文的攻击者,包括ppp(4)连接的远端,可以导致内核忙碌、获得敏感信息或权限提升。
英文描述:
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| freebsd | freebsd | 4.11 | - | - |
cpe:2.3:o:freebsd:freebsd:4.11:*:*:*:*:*:*:*
|
| freebsd | freebsd | 5.3 | - | - |
cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*
|
| freebsd | freebsd | 5.4 | - | - |
cpe:2.3:o:freebsd:freebsd:5.4:*:*:*:*:*:*:*
|
| freebsd | freebsd | 5.5 | - | - |
cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*
|
| freebsd | freebsd | 6.0 | - | - |
cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*
|
| freebsd | freebsd | 6.1 | - | - |
cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*
|
| netbsd | netbsd | 2.0 | - | - |
cpe:2.3:o:netbsd:netbsd:2.0:*:*:*:*:*:*:*
|
| netbsd | netbsd | 3.0 | - | - |
cpe:2.3:o:netbsd:netbsd:3.0:*:*:*:*:*:*:*
|
| netbsd | netbsd | 4.0 | - | - |
cpe:2.3:o:netbsd:netbsd:4.0:*:*:*:*:*:*:*
|
| openbsd | openbsd | 3.8 | - | - |
cpe:2.3:o:openbsd:openbsd:3.8:*:*:*:*:*:*:*
|
| openbsd | openbsd | 3.9 | - | - |
cpe:2.3:o:openbsd:openbsd:3.9:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:L/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2006-4304 |
2025-11-11 15:17:44 | 2025-11-11 07:32:36 |
| NVD | nvd_CVE-2006-4304 |
2025-11-11 14:51:50 | 2025-11-11 07:41:22 |
| CNNVD | cnnvd_CNNVD-200608-382 |
2025-11-11 15:08:52 | 2025-11-11 07:49:09 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200608-382
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 10.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 11
- data_sources: ['cve'] -> ['cve', 'nvd']